CVE-2026-74994
Received
Received - Intake
Authentication Bypass in OTP inets HTTP Server
Vulnerability report for CVE-2026-74994, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-01
Last updated on: 2026-09-01
Assigner: EEF
Description
Description
The mod_auth module in OTP's inets httpd server, when configured with dets or mnesia authentication backends and multiple directory configuration blocks, collapses all directory blocks into a single shared user/group namespace. A user added to one protected directory is accepted as valid for all other protected directories on the same server instance.
This issue affects OTP from OTPΒ 17.0 before OTPΒ 27.3.4.17, from OTPΒ 28.0 before OTPΒ 28.5.0.6, and from OTPΒ 29.0 before OTPΒ 29.0.6, corresponding to inets from 5.10 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 before 9.7.2. Whether OTP before OTPΒ 17.0, corresponding to inets before 5.10, is affected is unknown.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| erlang | otp | From 17.0 (inc) to 27.3.4.17 (exc) |
| erlang | otp | From 28.0 (inc) to 28.5.0.6 (exc) |
| erlang | otp | From 29.0 (inc) to 29.0.6 (exc) |
| erlang | inets | From 5.10 (inc) to 9.3.2.7 (exc) |
| erlang | inets | From 9.4 (inc) to 9.6.2.3 (exc) |
| erlang | inets | From 9.7 (inc) to 9.7.2 (exc) |
| erlang | otp | From 17.0 (exc) to 27.3.4.17 (exc) |
| erlang | otp | From 28.0 (exc) to 28.5.0.6 (exc) |
| erlang | otp | From 29.0 (exc) to 29.0.6 (exc) |
| erlang | inets | From 5.10 (exc) to 9.3.2.7 (exc) |
| erlang | inets | From 9.4 (exc) to 9.6.2.3 (exc) |
| erlang | inets | From 9.7 (exc) to 9.7.2 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-1289 | The product receives an input value that is used as a resource identifier or other type of reference, but it does not validate or incorrectly validates that the input is equivalent to a potentially-unsafe value. |
| CWE-863 | The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. |