Authentication Namespace Issue in OTP's inets HTTPD Server by Erlang
CVE-2026-74994

6MEDIUM

Key Information:

Vendor

Erlang

Status
Vendor
CVE Published:
1 September 2026

What is CVE-2026-74994?

The mod_auth module in OTP's inets HTTPD server, when configured with dets or mnesia authentication backends alongside multiple directory configurations, results in a shared user/group namespace. This means that an authenticated user in one protected directory is recognized across all other protected directories on the server instance, potentially compromising the security of segregated directories. This issue affects several versions of OTP and inets, necessitating prompt updates and configuration reviews.

Affected Version(s)

OTP 17.0 < 27.3.4.17

OTP 28.0 < 28.5.0.6

OTP 29.0 < 29.0.6

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Lukas Backström / Erlang Solutions
Konrad Pietrzak
.