OVERVIEW CVE-2026-28808 is an incorrect authorization vulnerability in Erlang OTP's inets HTTP server modules that enables unauthenticated access to CGI scripts protected by directory-based access controls. The flaw arises from a path mismatch between the mod_auth module, which evaluates access rules against DocumentRoot-relative paths, and the mod_cgi module, which executes scripts at their ScriptAlias-resolved locations. This discrepancy allows attackers to bypass authentication mechanisms when scripts are served through script_alias directives. The vulnerability affects Erlang OTP versions 17.0 through 28.4.2 and corresponding inets library versions 5.10 through 9.6.2, with specific patched releases available for OTP 26.2.5.19, 27.3.4.10, and 28.4.2. SEVERITY The attack requires no authentication and presents a network-accessible attack vector with low complexity, as attackers simply request protected CGI scripts through the misconfigured script_alias path. The potential impact is significant, as successful exploitation results in unauthorized access to scripts that administrators intended to restrict, potentially leading to information disclosure or unauthorized actions depending on script functionality. The CVSS score is not yet publicly assigned, though the FAUCET Risk Score of 50.0/100 suggests moderate concern. EXPLOITATION STATUS There is no indication of active exploitation, as the vulnerability is not listed on the Known Exploited Vulnerabilities catalog and shows no evidence of public exploit code availability. Community attention appears limited, reflected in the extremely low EPSS score of 0.0002, suggesting this vulnerability ranks among the lowest in terms of real-world exploitation probability across all CVEs.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.10, < 9.1.0.6CPE matchmatch criteria | cpe:2.3:a:erlang:erlang\/inets:*:*:*:*:*:*:*:* | ||
> 9.2, < 9.3.2.4CPE matchmatch criteria | cpe:2.3:a:erlang:erlang\/inets:*:*:*:*:*:*:*:* | ||
> 9.4, < 9.6.2CPE matchmatch criteria | cpe:2.3:a:erlang:erlang\/inets:*:*:*:*:*:*:*:* | ||
>= 17.0, < 26.2.5.19CPE matchmatch criteria | cpe:2.3:a:erlang:erlang\/otp:*:*:*:*:*:*:*:* | ||
>= 27.0, < 27.3.4.10CPE matchmatch criteria | cpe:2.3:a:erlang:erlang\/otp:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.