Impact
An improper handling of case sensitivity in Drupal External Authentication can lead to privilege escalation. The flaw allows an attacker to gain elevated rights by exploiting case‑folded comparisons during the authentication process. The vulnerability specifically targets the authentication logic and can compromise the confidentiality, integrity, and availability of the Drupal site when an attacker can authenticate with a user name that differs only in letter case.
Affected Systems
The affected system is Drupal External Authentication. Versions from 0.0.0 through 2.0.13 are vulnerable. All Drupal sites using one of these versions for external authentication are at risk.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, indicating no publicly known exploit activity yet. The likely attack vector is remote web access via standard HTTP(S) transport, as the flaw can be triggered by sending authentication requests to the Drupal site. Because the flaw is purely in the authentication logic, any authenticated or unauthenticated user with network access to the Drupal instance could potentially trigger the bypass if the correct username case is supplied.
OpenCVE Enrichment