CVE-2026-28808Disclosure(erlang / erlang\/inets)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Incorrect Authorization vulnerability in Erlang OTP (inets modules) allows unauthenticated access to CGI scripts protected by directory rules when served via script_alias. When script_alias maps a URL prefix to a directory outside DocumentRoot, mod_auth evaluates directory-based access controls against the DocumentRoot-relative path while mod_cgi executes the script at the ScriptAlias-resolved path. This path mismatch allows unauthenticated access to CGI scripts that directory rules were meant to protect. This vulnerability is associated with program files lib/inets/src/http_server/mod_alias.erl, lib/inets/src/http_server/mod_auth.erl, and lib/inets/src/http_server/mod_cgi.erl. This issue affects OTP from OTP 17.0 before OTP 26.2.5.19, OTP 27.3.4.10, and OTP 28.4.2, corresponding to inets from 5.10 before 9.1.0.6, 9.3.2.4, and 9.6.2. Whether OTP before OTP 17.0, corresponding to inets before 5.10, is affected is unknown.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863CWE-551

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • erlang\/inets
  • erlang\/otp

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-04-07); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
erlang\/inetserlang\/otp

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-07: 1Mentions · 2026-04-19: 1Technical Details · 2026-04-07: 1Technical Details · 2026-04-19: 104-0704-19
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-28808 Incorrect Authorization in Erlang OTP Inets Modules via Script Alias Path Mismatch https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-28808

    Post summary

    The post reports CVE-2026-28808 as an incorrect authorization flaw in Erlang OTP’s Inets modules caused by a script alias path mismatch, without providing exploit details, patch information, or evidence of active exploitation.

    0000170
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-28808 Incorrect Authorization vulnerability in Erlang OTP (inets modules) allows unauthenticated access to CGI scripts protected by directory rules when served via script_a… https://www.cve.org/CVERecord?id=CVE-2026-28808

    Post summary

    The text announces CVE-2026-28808, describing an authorization bypass in Erlang OTP's inets modules that permits unauthenticated access to protected CGI scripts.

    00000180
    57.2K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Apperlangerlang\/inets---
Apperlangerlang\/otp---

Explore more