openssl_encrypt versions before 1.4.0 accept refresh tokens as URL query parameters in keyserver and telemetry server routes. Attackers can extract tokens from server logs, proxy logs, browser history, and HTTP Referer headers to gain unauthorized access.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-74880 is a critical vulnerability in openssl_encrypt versions before 1.4.0 that exposes sensitive refresh tokens through URL query parameters on keyserver and telemetry server routes. This design flaw allows attackers to harvest authentication credentials from multiple sources: server access logs, proxy logs, browser history, and HTTP Referer headers—all locations where URLs are routinely stored and transmitted. Organizations using affected versions face immediate risk of unauthorized access, token hijacking, and lateral movement. The vulnerability affects any deployment relying on openssl_encrypt for authentication token handling, making it a widespread threat across cloud infrastructure, API gateways, and identity management systems.
While this CVE shows zero matching skills in Casky's current 754-skill framework (indicating a gap in existing detections), practitioners using Casky's Claude AI with extended reasoning capabilities would identify attack patterns aligned with MITRE ATT&CK's credential access techniques. Security teams should look for suspicious behaviors including: unusual token reuse across different IP addresses or geographic locations, tokens appearing in access logs with abnormal query string patterns, and spike in failed authentication attempts followed by successful ones using harvested tokens. Organizations should immediately audit logs for token exposure, upgrade to openssl_encrypt 1.4.0+, implement token parameter binding to prevent replay attacks, and transition to secure HTTP-only, SameSite-restricted cookie-based token handling to eliminate query parameter token transmission entirely.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-74880. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation