Logo
vulnerabilityCVE-2026-28808
Name
CVE-2026-28808
Source
NVD ( link)Debian ( link)
Description
Incorrect Authorization vulnerability in Erlang OTP (inets modules) allows unauthenticated access to CGI scripts protected by directory rules when served via script_alias. When script_alias maps a URL prefix to a directory outside DocumentRoot, mod_auth evaluates directory-based access controls against the DocumentRoot-relative path while mod_cgi executes the script at the ScriptAlias-resolved path. This path mismatch allows unauthenticated access to CGI scripts that directory rules were meant to protect. This vulnerability is associated with program files lib/inets/src/http_server/mod_alias.erl, lib/inets/src/http_server/mod_auth.erl, and lib/inets/src/http_server/mod_cgi.erl. This issue affects OTP from OTP 17.0 until OTP 28.4.2, 27.3.4.10 and 26.2.5.19 corresponding to inets from 5.10 until 9.6.2, 9.3.2.4 and 9.1.0.6.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
erlang
Exploitable

Vulnerability Ratings#


8.3
CVSSv4
9.8
CVSSv31
NaN
other

Others affected component#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
26.2.5.15
Exploitable