IP Address Authentication Flaw in Erlang/OTP's SSL Module
CVE-2026-48860
7.5HIGH
What is CVE-2026-48860?
A vulnerability exists in the Erlang/OTP SSL module's handling of IP address authentication. The inet_tls_dist:check_ip/1 function incorrectly retrieves the peer's IP address using inet:sockname/1, which returns the local socket address instead of the true remote address. This design flaw allows attackers with a CA-signed TLS certificate to circumvent the LAN allowlist policies and gain unauthorized access to Erlang distribution functionalities, including remote procedure calls and code loading. This vulnerability impacts various versions of Erlang/OTP and its associated SSL implementations.
Affected Version(s)
OTP 11.0
OTP 26.0
OTP 7a08c5507862a7011568506d0c17b1fdef30bee4 < 0209a6df65d605552b378273027b3968b35f26b4
References
CVSS V4
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Lukas Backström
Ingela Anderton Andin
Raimo Niskanen
Jakub Witczak
