Improper Handling of Case Sensitivity in Erlang OTP - CVE-2026-73270
Published: September 2, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication and access protected resources.
The vulnerability exists due to improper handling of case sensitivity in the mod_auth module in OTP\'s inets httpd server when processing requests for protected directory paths on case-insensitive filesystems. A remote attacker can request the same protected resource using different path casing to bypass authentication and access protected resources.
Only deployments on case-insensitive filesystems such as Windows and macOS are vulnerable, and exploitation requires one or more directory blocks configured with mod_auth.