A vulnerability, which was classified as problematic, has been found in jahlives openssl_encrypt up to 1.3.x. Affected by this vulnerability is an unknown functionality. The manipulation leads to permissive cross-domain policy with untrusted domains.

This vulnerability is traded as CVE-2026-74881. It is possible to initiate the attack remotely. There is no exploit available.

It is advisable to upgrade the affected component.