Drupal External Auth: Improper Case Handling, v<2.0.13
CVE-2026-73476 Published on September 2, 2026
External Authentication - Moderately critical - Access bypass - SA-CONTRIB-2026-098
Improper Handling of Case Sensitivity vulnerability in Drupal External Authentication allows Privilege Escalation. This issue affects External Authentication versions: from 0.0.0 to 2.0.13.
Vulnerability Analysis
CVE-2026-73476 is exploitable with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a small impact on confidentiality and integrity, and no impact on availability.
Weakness Type
Improper Handling of Case Sensitivity
The software does not properly account for differences in case sensitivity when accessing or determining the properties of a resource, leading to inconsistent results.
Affected Versions
Drupal External Authentication:- Version 0.0.0 and below 2.0.13 is affected.