Zum Inhalt springen.
Sympa Menü

it-securitynotifies - [IT-SecNots] [Security-news] External Authentication - Moderately critical - Access bypass - SA-CONTRIB-2026-098

it-securitynotifies AT lists.piratenpartei.de

Betreff: Sicherheitsankündigungen

Listenarchiv

[IT-SecNots] [Security-news] External Authentication - Moderately critical - Access bypass - SA-CONTRIB-2026-098


Chronologisch Thread  
  • From: security-news AT drupal.org
  • To: security-news AT drupal.org
  • Subject: [IT-SecNots] [Security-news] External Authentication - Moderately critical - Access bypass - SA-CONTRIB-2026-098
  • Date: Wed, 12 Aug 2026 17:56:04 +0000
  • Archived-at: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/message/BHO772XXV7EOWCIONSNE6PLODYVR4VCT/>
  • Authentication-results: lists.piratenpartei.de; dkim=pass header.d=drupal.org header.s=default header.b=J4JpM7jN; dkim=fail ("body hash did not verify") header.d=drupal.org header.s=f34odw3mfzgsrgyn3evjayysxxl6jizn header.b=qh7zmOET; dkim=fail ("body hash did not verify") header.d=amazonses.com header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=COa3jW9Z; dmarc=pass (policy=none) header.from=drupal.org; spf=pass (lists.piratenpartei.de: domain of security-news-bounces AT drupal.org designates 2605:bc80:3010::133 as permitted sender) smtp.mailfrom=security-news-bounces AT drupal.org
  • Dkim-filter: OpenDKIM Filter v2.11.0 smtp2.osuosl.org 3E19841630
  • Dkim-filter: OpenDKIM Filter v2.11.0 smtp2.osuosl.org 1965F40073
  • Dmarc-filter: OpenDMARC Filter v1.4.2 smtp2.osuosl.org 1965F40073
  • Feedback-id: ::1.us-west-2.eaokZ1GT8utLqfMHQoyOsEFVrSIzzS6R+14LP6WIIUY=:AmazonSES
  • List-archive: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/>
  • List-id: <security-news.drupal.org>

View online: https://www.drupal.org/sa-contrib-2026-098

Project: External Authentication [1]
Date: 2026-August-12
Security risk: *Moderately critical* 13 ∕ 25
AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:Default [2]
Vulnerability: Access bypass

Affected versions: <2.0.13
CVE IDs: CVE-2026-73476
Description: 
This module enables you to authenticate Drupal users against external
identity providers.
The module does not sufficiently ensure exact matching of externally supplied
identity values when storing and looking up authentication mappings under
certain database collation configurations.
This vulnerability is mitigated by the fact that it affects only sites using
impacted MySQL or MariaDB collation settings for the module’s
authentication mapping storage.

Solution: 
Install the latest version:

* If you use the externalauth module for Drupal, upgrade to 2.0.13 [3]

Reported By: 
* 晉宇 林 (whale120) [4]

Fixed By: 
* Sven Decabooter (svendecabooter) [5]

Coordinated By: 
* Swan Kalata (akalata) [6] of the Drupal Security Team
* Neil Drumm (drumm) [7] of the Drupal Security Team
* Greg Knaddison (greggles) [8] of the Drupal Security Team
* Juraj Nemec (poker10) [9] of the Drupal Security Team

------------------------------------------------------------------------------
Contribution record [10]

[1] https://www.drupal.org/project/externalauth
[2] https://www.drupal.org/security-team/risk-levels
[3] https://www.drupal.org/project/externalauth/releases/2.0.13
[4] https://www.drupal.org/u/whale120
[5] https://www.drupal.org/u/svendecabooter
[6] https://www.drupal.org/u/akalata
[7] https://www.drupal.org/u/drumm
[8] https://www.drupal.org/u/greggles
[9] https://www.drupal.org/u/poker10
[10] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal.org/node/3610827

_______________________________________________
Security-news mailing list -- security-news AT drupal.org
To unsubscribe send an email to security-news-leave AT drupal.org
Unsubscribe at

  • [IT-SecNots] [Security-news] External Authentication - Moderately critical - Access bypass - SA-CONTRIB-2026-098, security-news, 12.08.2026

Archiv bereitgestellt durch MHonArc 2.6.19+.

Seitenanfang