Incorrect Comparison in Etherpad - #VU151607

 

Incorrect Comparison in Etherpad - #VU151607

Published: September 22, 2026


Vulnerability identifier: #VU151607
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-697
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to authenticate as an account without a usable password and perform HTTP API actions gated on the admin claim.

The vulnerability exists due to incorrect comparison in the embedded OpenID Connect provider interactive login when processing login credentials. A remote attacker can submit the literal "undefined" or "null" as a password to authenticate as the targeted account and perform HTTP API actions gated on the admin claim.

Exploitation requires the default SSO authentication method with configured SSO clients, a known username, and an account whose password is missing or JSON null.


Affected software

Etherpad

Remediation

Install security update from vendor's website.

Etherpad - update to 3.3.6

External References

Related Security Bulletins