CVE-2026-74994
Received Received - Intake

Authentication Bypass in OTP inets HTTP Server

Vulnerability report for CVE-2026-74994, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-01

Last updated on: 2026-09-01

Assigner: EEF

Description

The mod_auth module in OTP's inets httpd server, when configured with dets or mnesia authentication backends and multiple directory configuration blocks, collapses all directory blocks into a single shared user/group namespace. A user added to one protected directory is accepted as valid for all other protected directories on the same server instance. This issue affects OTP from OTPΒ 17.0 before OTPΒ 27.3.4.17, from OTPΒ 28.0 before OTPΒ 28.5.0.6, and from OTPΒ 29.0 before OTPΒ 29.0.6, corresponding to inets from 5.10 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 before 9.7.2. Whether OTP before OTPΒ 17.0, corresponding to inets before 5.10, is affected is unknown.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-01
Last Modified
2026-09-01
Generated
2026-09-01
AI Q&A
2026-09-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 12 associated CPEs
Vendor Product Version / Range
erlang otp From 17.0 (inc) to 27.3.4.17 (exc)
erlang otp From 28.0 (inc) to 28.5.0.6 (exc)
erlang otp From 29.0 (inc) to 29.0.6 (exc)
erlang inets From 5.10 (inc) to 9.3.2.7 (exc)
erlang inets From 9.4 (inc) to 9.6.2.3 (exc)
erlang inets From 9.7 (inc) to 9.7.2 (exc)
erlang otp From 17.0 (exc) to 27.3.4.17 (exc)
erlang otp From 28.0 (exc) to 28.5.0.6 (exc)
erlang otp From 29.0 (exc) to 29.0.6 (exc)
erlang inets From 5.10 (exc) to 9.3.2.7 (exc)
erlang inets From 9.4 (exc) to 9.6.2.3 (exc)
erlang inets From 9.7 (exc) to 9.7.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1289 The product receives an input value that is used as a resource identifier or other type of reference, but it does not validate or incorrectly validates that the input is equivalent to a potentially-unsafe value.
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The mod_auth module in OTP's inets httpd server has a flaw where directory authentication blocks are merged into one shared namespace. This means a user granted access to one protected directory automatically gains access to all other protected directories on the same server instance.

Detection Guidance

To detect this vulnerability, check if your Erlang/OTP inets httpd server is running a vulnerable version (OTP < 27.3.4.17, 28.0 < 28.5.0.6, 29.0 < 29.0.6 or inets < 9.3.2.7, 9.4 < 9.6.2.3, 9.7 < 9.7.2) with dets or mnesia authentication backends and multiple directory blocks. Verify if user records are shared across directories by testing authentication in different protected paths.

Impact Analysis

This vulnerability allows unauthorized users to access restricted directories if they have credentials for any single protected directory. It undermines access controls and could lead to data breaches or privilege escalation within the server.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data across multiple directories, violating confidentiality requirements in GDPR and HIPAA. It allows users authenticated for one directory to access others, potentially exposing protected health or personal information.

Mitigation Strategies

Upgrade OTP to version 27.3.4.17 or later, 28.5.0.6 or later, or 29.0.6 or later. Also upgrade inets to version 9.3.2.7 or later, 9.6.2.3 or later, or 9.7.2 or later depending on your OTP version.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-74994. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart