SB2026092233 - Incorrect Comparison in Etherpad



SB2026092233 - Incorrect Comparison in Etherpad

Published: September 22, 2026

Security Bulletin ID SB2026092233
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Incorrect Comparison (CVE-ID: N/A)

CWE-ID: CWE-697 - Incorrect Comparison

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to authenticate as an account without a usable password and perform HTTP API actions gated on the admin claim.

The vulnerability exists due to incorrect comparison in the embedded OpenID Connect provider interactive login when processing login credentials. A remote attacker can submit the literal "undefined" or "null" as a password to authenticate as the targeted account and perform HTTP API actions gated on the admin claim.

Exploitation requires the default SSO authentication method with configured SSO clients, a known username, and an account whose password is missing or JSON null.


Remediation

Install update from vendor's website.