Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-37026

31
FAUCET Score

CVE-2022-37026 is a critical client authentication bypass vulnerability affecting Erlang/OTP versions prior to 23.3.4.15, 24.3.4.2, and 25.0.2 in SSL, TLS, and DTLS contexts. With a CVSS score of 9.8, this vulnerability allows unauthenticated attackers to achieve high impact on confidentiality, integrity, and availability over the network with low attack complexity. While there is no evidence of active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion with 10 mentions, indicating awareness.

Impacted Technologies

VendorProductVersion(s)CPE
< 23.3.4.15CPE matchmatch criteria
cpe:2.3:a:erlang:erlang\/otp:*:*:*:*:*:*:*:*
>= 24.0, < 24.3.4.2CPE matchmatch criteria
cpe:2.3:a:erlang:erlang\/otp:*:*:*:*:*:*:*:*
>= 25.0, < 25.0.2CPE matchmatch criteria
cpe:2.3:a:erlang:erlang\/otp:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.8CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.21%
Probability of exploitation in next 30 days
EPSS Percentile
65.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0121 is in the 51st percentile among its peer group of 36,862 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (6)

coollabspatch availablevia llm_extracted
github_advisorypatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenStack Platform 16.2Fixed in: erlang-0:23.3.4.18-1.el8ost
View patch
power_bivendor investigatingvia llm_extracted
redhatend of lifevia redhat_api
Product: Red Hat OpenStack Platform 13 (Queens)Fixed in: erlang
redhatend of lifevia redhat_api
Product: Red Hat OpenStack Platform 16.1Fixed in: erlang

Vendor Advisories (3)

coollabsllm-coollabs-e8500baeec024f77CRITICAL

LenelS2 OnGuard Client Authentication Bypass Vulnerability

Nov 30, 2022
power_billm-power_bi-a29f30546c8bb118CRITICAL

LenelS2 OnGuard Client Authentication Bypass Vulnerability

Nov 30, 2022
redhatCVE-2022-37026Critical

erlang/otp: Client Authentication Bypass

Sep 21, 2022

References

erlangforums.com / c/erlang-news-announcements/91
Release NotesVendor Advisory
erlangforums.com / t/otp-25-1-released/1854
Release NotesVendor Advisory
github.com / erlang/otp/compare/OTP-23.3.4.14...OTP-23.3.4.15
PatchThird Party Advisory
lists.debian.org / debian-lts-announce/2023/07/msg00012.html