Description
Improper Handling of Case Sensitivity vulnerability in Drupal External Authentication allows Privilege Escalation. This issue affects External Authentication versions: from 0.0.0 to 2.0.13.
Published: 2026-09-02
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper handling of case sensitivity in Drupal External Authentication can lead to privilege escalation. The flaw allows an attacker to gain elevated rights by exploiting case‑folded comparisons during the authentication process. The vulnerability specifically targets the authentication logic and can compromise the confidentiality, integrity, and availability of the Drupal site when an attacker can authenticate with a user name that differs only in letter case.

Affected Systems

The affected system is Drupal External Authentication. Versions from 0.0.0 through 2.0.13 are vulnerable. All Drupal sites using one of these versions for external authentication are at risk.

Risk and Exploitability

The CVSS score of 5.4 indicates moderate severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, indicating no publicly known exploit activity yet. The likely attack vector is remote web access via standard HTTP(S) transport, as the flaw can be triggered by sending authentication requests to the Drupal site. Because the flaw is purely in the authentication logic, any authenticated or unauthenticated user with network access to the Drupal instance could potentially trigger the bypass if the correct username case is supplied.

Generated by OpenCVE AI on September 3, 2026 at 10:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Drupal External Authentication to 2.0.14 or newer when a patch is released.
  • If an upgrade cannot be performed immediately, disable the External Authentication module until the issue is resolved.
  • Review and enforce strict case‑sensitive authentication rules in the site's authentication configuration and monitor logs for anomalous login attempts.

Generated by OpenCVE AI on September 3, 2026 at 10:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Thu, 03 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 02 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


Wed, 02 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Drupal
Drupal external Authentication
Vendors & Products Drupal
Drupal external Authentication

Wed, 02 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Description Improper Handling of Case Sensitivity vulnerability in Drupal External Authentication allows Privilege Escalation. This issue affects External Authentication versions: from 0.0.0 to 2.0.13.
Title External Authentication - Moderately critical - Access bypass - SA-CONTRIB-2026-098
Weaknesses CWE-178
References

Subscriptions

Drupal External Authentication
cve-icon MITRE

Status: PUBLISHED

Assigner: drupal

Published:

Updated: 2026-09-02T18:38:42.486Z

Reserved: 2026-08-12T17:21:18.776Z

Link: CVE-2026-73476

cve-icon Vulnrichment

Updated: 2026-09-02T18:38:33.038Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-02T13:18:08.413

Modified: 2026-09-02T19:18:02.303

Link: CVE-2026-73476

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T10:15:05Z

Weaknesses
  • CWE-178

    Improper Handling of Case Sensitivity