PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-28808 Erlang CVE debrief

CVE-2026-28808 is an Incorrect Authorization vulnerability in Erlang OTP's inets modules, allowing unauthenticated access to CGI scripts protected by directory rules when served via script_alias. The vulnerability affects OTP from version 17.0 before OTP 26.2.5.19, OTP 27.3.4.10, and OTP 28.4.2, corresponding to inets from version 5.10 before 9.1.0.6, 9.3.2.4, and 9.6.2. The impact and remediation details are still being verified.

Vendor
Erlang
Product
OTP
CVSS
HIGH 8.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-07
Original CVE updated
2026-09-08
Advisory published
2026-04-07
Advisory updated
2026-09-08

Who should care

Defenders and administrators of systems using Erlang OTP's inets modules should verify exposure and apply patches or mitigations to prevent unauthorized access to protected CGI scripts.

Why it matters

CVE-2026-28808 is a high-severity vulnerability in Erlang OTP's inets modules, allowing unauthenticated access to protected CGI scripts. Defenders should verify exposure, apply patches or mitigations, and review access controls to prevent exploitation.

  • Verify exposure and apply patches or mitigations to prevent unauthorized access
  • Review and update access controls for CGI scripts
  • Monitor for potential exploitation attempts

Technical summary

The vulnerability occurs due to a path mismatch between mod_auth and mod_cgi in Erlang OTP's inets modules, allowing unauthenticated access to CGI scripts protected by directory rules. This path mismatch allows unauthenticated access to CGI scripts that directory rules were meant to protect. The issue affects OTP from OTP 17.0 before OTP 26.2.5.19, OTP 27.3.4.10, and OTP 28.4.2, corresponding to inets from 5.10 before 9.1.0.6, 9.3.2.4, and 9.6.2. The vulnerability is associated with program files lib/inets/src/http_server/mod_alias.erl, lib/inets/src/http_server/mod_auth.erl, and lib/inets/src/http_server/mod_cgi.erl.

Defensive priority

Defenders should prioritize verifying exposure and applying patches or mitigations, as the vulnerability allows unauthorized access to protected CGI scripts.

Recommended defensive actions

  • Verify exposure by checking OTP and inets versions
  • Apply patches or mitigations from Erlang
  • Review and update access controls for CGI scripts
  • Monitor for potential exploitation attempts
  • Perform a thorough review of system configurations and update documentation
  • Consider implementing compensating controls for exposed systems
  • Track exceptions and retest remediated assets

Evidence notes

The CVE record and NVD detail page provide information on the vulnerability, while vendor advisories and patches are available from Erlang and other sources. Defenders should verify exposure by checking OTP and inets versions, review and update access controls for CGI scripts, and monitor for potential exploitation attempts. The vulnerability affects OTP from version 17.0 before OTP 26.2.5.19, OTP 27.3.4.10, and OTP 28.4.2, corresponding to inets from version 5.10 before 9.1.0.6, 9.3.2.4, and 9.6.2. Whether OTP before OTP 17.0, inets

Sources and references

Verified primary and authoritative sources

  • CVE-2026-28808 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-28808

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-28808 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-28808

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://cna.erlef.org/cves/CVE-2026-28808.html

    6b3ad84c-e1a6-4bf7-a703-f496b71e49db - Mitigation, Vendor Advisory

  • Source reference

    Unverified legacy reference

    URL: https://github.com/erlang/otp/commit/07b8f441ca711f9812fad9e9115bab3c3aa92f79

    6b3ad84c-e1a6-4bf7-a703-f496b71e49db

  • Source reference

    Unverified legacy reference

    URL: https://github.com/erlang/otp/commit/8fc71ac6af4fbcc54103bec2983ef22e82942688

    6b3ad84c-e1a6-4bf7-a703-f496b71e49db - Patch

  • Source reference

    Unverified legacy reference

    URL: https://github.com/erlang/otp/commit/9dfa0c51eac97866078e808dec2183cb7871ff7c

    6b3ad84c-e1a6-4bf7-a703-f496b71e49db - Patch

  • Source reference

    Unverified legacy reference

    URL: https://github.com/erlang/otp/security/advisories/GHSA-3vhp-h532-mc3f

    6b3ad84c-e1a6-4bf7-a703-f496b71e49db - Third Party Advisory

  • Source reference

    Unverified legacy reference

    URL: https://osv.dev/vulnerability/EEF-CVE-2026-28808

    6b3ad84c-e1a6-4bf7-a703-f496b71e49db - Patch, Third Party Advisory

  • Source reference

    Unverified legacy reference

    URL: https://www.erlang.org/doc/system/versions.html

    6b3ad84c-e1a6-4bf7-a703-f496b71e49db - Product

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/security/cve/CVE-2026-28808

    0b0ca135-0b70-47e7-9f44-1890c2a1c46c

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.