Privilege Escalation Vulnerability in Drupal External Authentication
CVE-2026-73476

Currently unrated

Key Information:

Vendor

Drupal

Vendor
CVE Published:
2 September 2026

What is CVE-2026-73476?

The vulnerability in Drupal's External Authentication is due to improper handling of case sensitivity, which allows an attacker to escalate privileges. This security flaw can be exploited in versions from 0.0.0 to 2.0.13, creating potential unauthorized access to sensitive functionalities. Website administrators using these affected versions are advised to implement the latest patches to safeguard against this vulnerability.

Affected Version(s)

External Authentication 0.0.0 < 2.0.13

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

晉宇 林 (whale120)
Sven Decabooter (svendecabooter)
Swan Kalata (akalata)
Neil Drumm (drumm)
Greg Knaddison (greggles)
Juraj Nemec (poker10)
.