Drupal · External Authentication · CVE-2026-73476
**Name of the Vulnerable Software and Affected Versions**
Drupal External Authentication versions 0.0.0 through 2.0.13
**Description**
Improper handling of case sensitivity allows privilege escalation. The module fails to ensure exact matching of externally supplied identity values when storing and looking up authentication mappings under specific database collation configurations. This issue primarily affects sites using certain MySQL or MariaDB collation settings for the authentication mapping storage.
**Recommendations**
Update Drupal External Authentication to a version newer than 2.0.13.