CVE-2026-73476 PUBLISHED

External Authentication - Moderately critical - Access bypass - SA-CONTRIB-2026-098

Assigner: drupal
Reserved: 12.08.2026 Published: 02.09.2026 Updated: 02.09.2026

Improper Handling of Case Sensitivity vulnerability in Drupal External Authentication allows Privilege Escalation. This issue affects External Authentication versions: from 0.0.0 to 2.0.13.

Product Status

Vendor Drupal
Product External Authentication
Versions
  • affected from 0.0.0 to 2.0.13 (excl.)

Credits

  • 晉宇 林 (whale120) finder
  • Sven Decabooter (svendecabooter) remediation developer
  • Swan Kalata (akalata) coordinator
  • Neil Drumm (drumm) coordinator
  • Greg Knaddison (greggles) coordinator
  • Juraj Nemec (poker10) coordinator

References

Problem Types

  • CWE-178 Improper Handling of Case Sensitivity CWE

Impacts

  • CAPEC-233 Privilege Escalation