PatchSiren cyber security CVE debrief
CVE-2026-28808 Erlang CVE debrief
CVE-2026-28808 is an Incorrect Authorization vulnerability in Erlang OTP's inets modules, allowing unauthenticated access to CGI scripts protected by directory rules when served via script_alias. The vulnerability affects OTP from version 17.0 before OTP 26.2.5.19, OTP 27.3.4.10, and OTP 28.4.2, corresponding to inets from version 5.10 before 9.1.0.6, 9.3.2.4, and 9.6.2. The impact and remediation details are still being verified.
- Vendor
- Erlang
- Product
- OTP
- CVSS
- HIGH 8.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-07
- Original CVE updated
- 2026-09-08
- Advisory published
- 2026-04-07
- Advisory updated
- 2026-09-08
Who should care
Defenders and administrators of systems using Erlang OTP's inets modules should verify exposure and apply patches or mitigations to prevent unauthorized access to protected CGI scripts.
Why it matters
CVE-2026-28808 is a high-severity vulnerability in Erlang OTP's inets modules, allowing unauthenticated access to protected CGI scripts. Defenders should verify exposure, apply patches or mitigations, and review access controls to prevent exploitation.
- Verify exposure and apply patches or mitigations to prevent unauthorized access
- Review and update access controls for CGI scripts
- Monitor for potential exploitation attempts
Technical summary
The vulnerability occurs due to a path mismatch between mod_auth and mod_cgi in Erlang OTP's inets modules, allowing unauthenticated access to CGI scripts protected by directory rules. This path mismatch allows unauthenticated access to CGI scripts that directory rules were meant to protect. The issue affects OTP from OTP 17.0 before OTP 26.2.5.19, OTP 27.3.4.10, and OTP 28.4.2, corresponding to inets from 5.10 before 9.1.0.6, 9.3.2.4, and 9.6.2. The vulnerability is associated with program files lib/inets/src/http_server/mod_alias.erl, lib/inets/src/http_server/mod_auth.erl, and lib/inets/src/http_server/mod_cgi.erl.
Defensive priority
Defenders should prioritize verifying exposure and applying patches or mitigations, as the vulnerability allows unauthorized access to protected CGI scripts.
Recommended defensive actions
- Verify exposure by checking OTP and inets versions
- Apply patches or mitigations from Erlang
- Review and update access controls for CGI scripts
- Monitor for potential exploitation attempts
- Perform a thorough review of system configurations and update documentation
- Consider implementing compensating controls for exposed systems
- Track exceptions and retest remediated assets
Evidence notes
The CVE record and NVD detail page provide information on the vulnerability, while vendor advisories and patches are available from Erlang and other sources. Defenders should verify exposure by checking OTP and inets versions, review and update access controls for CGI scripts, and monitor for potential exploitation attempts. The vulnerability affects OTP from version 17.0 before OTP 26.2.5.19, OTP 27.3.4.10, and OTP 28.4.2, corresponding to inets from version 5.10 before 9.1.0.6, 9.3.2.4, and 9.6.2. Whether OTP before OTP 17.0, inets
Sources and references
Verified primary and authoritative sources
-
CVE-2026-28808 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-28808
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-28808 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-28808
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://cna.erlef.org/cves/CVE-2026-28808.html
6b3ad84c-e1a6-4bf7-a703-f496b71e49db - Mitigation, Vendor Advisory
-
Source reference
Unverified legacy reference
URL: https://github.com/erlang/otp/commit/07b8f441ca711f9812fad9e9115bab3c3aa92f79
6b3ad84c-e1a6-4bf7-a703-f496b71e49db
-
Source reference
Unverified legacy reference
URL: https://github.com/erlang/otp/commit/8fc71ac6af4fbcc54103bec2983ef22e82942688
6b3ad84c-e1a6-4bf7-a703-f496b71e49db - Patch
-
Source reference
Unverified legacy reference
URL: https://github.com/erlang/otp/commit/9dfa0c51eac97866078e808dec2183cb7871ff7c
6b3ad84c-e1a6-4bf7-a703-f496b71e49db - Patch
-
Source reference
Unverified legacy reference
URL: https://github.com/erlang/otp/security/advisories/GHSA-3vhp-h532-mc3f
6b3ad84c-e1a6-4bf7-a703-f496b71e49db - Third Party Advisory
-
Source reference
Unverified legacy reference
URL: https://osv.dev/vulnerability/EEF-CVE-2026-28808
6b3ad84c-e1a6-4bf7-a703-f496b71e49db - Patch, Third Party Advisory
-
Source reference
Unverified legacy reference
URL: https://www.erlang.org/doc/system/versions.html
6b3ad84c-e1a6-4bf7-a703-f496b71e49db - Product
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/security/cve/CVE-2026-28808
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.