Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-73270

Erlang/OTP inets httpd mod_auth bypass through letter case on case-insensitive filesystems

Technology

Erlang/OTP

CVSS Score

8.2 / 10.0

Affected Versions

OTP 17.0 and later, before 27.3.4.17, 28.5.0.6 and 29.0.6 (inets)

Upstream Fix

OTP 27.3.4.17, 28.5.0.6, 29.0.6

Published

September 1, 2026

OSSeva Coverage

Fixed upstream

Description

mod_auth matches protected directories case-sensitively, so on a case-insensitive filesystem a remote, unauthenticated attacker can read protected files by requesting them with different capitalisation.

Upstream record: NVD · CVE.org

Is your Erlang/OTP deployment affected?

If you're running OTP 17.0 and later, before 27.3.4.17, 28.5.0.6 and 29.0.6 (inets), you need this patch. Book a discovery call to get covered.