Authentication Namespace Issue in OTP's inets HTTPD Server by Erlang
CVE-2026-74994
6MEDIUM
What is CVE-2026-74994?
The mod_auth module in OTP's inets HTTPD server, when configured with dets or mnesia authentication backends alongside multiple directory configurations, results in a shared user/group namespace. This means that an authenticated user in one protected directory is recognized across all other protected directories on the server instance, potentially compromising the security of segregated directories. This issue affects several versions of OTP and inets, necessitating prompt updates and configuration reviews.
Affected Version(s)
OTP 17.0 < 27.3.4.17
OTP 28.0 < 28.5.0.6
OTP 29.0 < 29.0.6
References
CVSS V4
Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Lukas Backström / Erlang Solutions
Konrad Pietrzak
