PT-2026-84268 · Erlang · Otp+1

·

CVE-2026-74994

·

Published

2026-09-01

·

Updated

2026-09-01

CVSS v4.0

6.0

Medium

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions OTP versions 17.0 through 27.3.4.16 OTP versions 28.0 through 28.5.0.5 OTP versions 29.0 through 29.0.5 inets versions 5.10 through 9.3.2.6 inets versions 9.4 through 9.6.2.2 inets versions 9.7 through 9.7.1
Description The mod auth module in the inets httpd server collapses all directory configuration blocks into a single shared user/group namespace when configured with dets or mnesia authentication backends. This behavior allows a user authorized for one protected directory to be accepted as valid for all other protected directories on the same server instance.
Recommendations Update OTP to version 27.3.4.17 or later. Update OTP to version 28.5.0.6 or later. Update OTP to version 29.0.6 or later. Update inets to version 9.3.2.7 or later. Update inets to version 9.6.2.3 or later. Update inets to version 9.7.2 or later.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-98496
CVE-2026-74994
GHSA-C3CQ-Q8X6-547G

Affected Products

Otp
Inets