Junglewise Threat Intelligence

CVE-2026-28808: Erlang OTP incorrect authorization in inets mod_auth

CVE-2026-28808 · Severity: critical · CVSS 9.8 · Published 2026-04-07

Technologies: Erlang Inets, Erlang OTP. Vendors: Erlang.

Executive brief

A security flaw in the Erlang OTP web server library (inets) allows unauthorized users to bypass security rules intended to protect web scripts. This occurs when the server is configured to run scripts from a specific directory outside of the main web folder. An attacker could exploit this to run sensitive scripts or access restricted data without providing the required credentials.

Technical details

An incorrect authorization vulnerability exists in the Erlang OTP 'inets' HTTP server due to a path mismatch between 'mod_auth' and 'mod_cgi'. When 'script_alias' is used to map a URL prefix to a directory outside the 'DocumentRoot', 'mod_auth' incorrectly evaluates directory-based access controls against the 'DocumentRoot'-relative path instead of the actual resolved path. Meanwhile, 'mod_cgi' executes the script at the correctly resolved 'ScriptAlias' path. This allows a remote, unauthenticated attacker to bypass authentication requirements for CGI scripts. The issue is fixed in OTP versions 28.4.2, 27.3.4.10, and 26.2.5.19.

Affected products

  • Erlang OTP 17.0 to 28.4.2, 27.3.4.10, 26.2.5.19
  • Erlang inets 5.10 to 9.6.2, 9.3.2.4, 9.1.0.6

Timeline

  • 2026-03-23: patched: Initial fix commits authored
  • 2026-04-07: advisory: Vulnerability published by NVD and Erlang Ecosystem Foundation

References

Related threats