Path Equivalence Vulnerability in Erlang/OTP inets httpd
CVE-2026-66835

8.2HIGH

Key Information:

Vendor

Erlang

Status
Vendor
CVE Published:
1 September 2026

What is CVE-2026-66835?

The path equivalence vulnerability in Erlang/OTP inets httpd allows a remote attacker to bypass authentication and access files within a protected directory. By prefixing the request path with an extra slash, the authentication mechanism fails to recognize the directory as protected, leading to unauthorized exposure of sensitive files. This occurs due to improper normalization of the request URI, specifically the handling of empty path segments, ultimately undermining the intended security framework of mod_auth.

Affected Version(s)

OTP 17.0 < 27.3.4.17

OTP 28.0 < 28.5.0.6

OTP 29.0 < 29.0.6

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Arthur Chan / Ada Logics
David Korczynski / Ada Logics
Adam Korczynski / Ada Logics
Konrad Pietrzak / Ericsson
.