CVE-2026-74994

MEDIUM CVSS 4.0: 6.0 EPSS 0.36%
Updated Sep 08, 2026
Erlang
Parameter Value
CVSS 6.0 (MEDIUM)
Affected Versions 28.0 — 29.0.6
Fixed In 27.3.4.17
Type CWE-863 (Incorrect Authorization), CWE-1289
Vendor Erlang
Public PoC No

The mod_auth module in OTP's inets httpd server, when configured with dets or mnesia authentication backends and multiple directory configuration blocks, collapses all directory blocks into a single shared user/group namespace. A user added to one protected directory is accepted as valid for all other protected directories on the same server instance. This issue affects OTP from OTP 17.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to inets from 5.10 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 before 9.7.2.

Whether OTP before OTP 17.0, corresponding to inets before 5.10, is affected is unknown.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Attack Requirements
Present
Additional conditions required
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
None
No data modification
Availability
None
No disruption

CVSS Vector v4.0

Vulnerable Products 3

Configuration From (including) Up to (excluding)
Erlang Erlang\/Otp
cpe:2.3:a:erlang:erlang\/otp:*:*:*:*:*:*:*:*
27.3.4.17
Erlang Erlang\/Otp
cpe:2.3:a:erlang:erlang\/otp:*:*:*:*:*:*:*:*
28.0 28.5.0.6
Erlang Erlang\/Otp
cpe:2.3:a:erlang:erlang\/otp:*:*:*:*:*:*:*:*
29.0 29.0.6