SB2026092233 - Incorrect Comparison in Etherpad
Published: September 22, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Incorrect Comparison (CVE-ID: N/A)
CWE-ID: CWE-697 - Incorrect Comparison
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to authenticate as an account without a usable password and perform HTTP API actions gated on the admin claim.
The vulnerability exists due to incorrect comparison in the embedded OpenID Connect provider interactive login when processing login credentials. A remote attacker can submit the literal "undefined" or "null" as a password to authenticate as the targeted account and perform HTTP API actions gated on the admin claim.
Exploitation requires the default SSO authentication method with configured SSO clients, a known username, and an account whose password is missing or JSON null.
Remediation
Install update from vendor's website.