Incorrect Comparison in Etherpad - #VU151607
Published: September 22, 2026
Vulnerability details
The vulnerability allows a remote attacker to authenticate as an account without a usable password and perform HTTP API actions gated on the admin claim.
The vulnerability exists due to incorrect comparison in the embedded OpenID Connect provider interactive login when processing login credentials. A remote attacker can submit the literal "undefined" or "null" as a password to authenticate as the targeted account and perform HTTP API actions gated on the admin claim.
Exploitation requires the default SSO authentication method with configured SSO clients, a known username, and an account whose password is missing or JSON null.