IP Address Authentication Flaw in Erlang/OTP's SSL Module
CVE-2026-48860

7.5HIGH

Key Information:

Vendor

Erlang

Status
Vendor
CVE Published:
10 June 2026

What is CVE-2026-48860?

A vulnerability exists in the Erlang/OTP SSL module's handling of IP address authentication. The inet_tls_dist:check_ip/1 function incorrectly retrieves the peer's IP address using inet:sockname/1, which returns the local socket address instead of the true remote address. This design flaw allows attackers with a CA-signed TLS certificate to circumvent the LAN allowlist policies and gain unauthorized access to Erlang distribution functionalities, including remote procedure calls and code loading. This vulnerability impacts various versions of Erlang/OTP and its associated SSL implementations.

Affected Version(s)

OTP 11.0

OTP 26.0

OTP 7a08c5507862a7011568506d0c17b1fdef30bee4 < 0209a6df65d605552b378273027b3968b35f26b4

References

CVSS V4

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Lukas Backström
Ingela Anderton Andin
Raimo Niskanen
Jakub Witczak
.