CVE-2026-73476: External Authentication Project External Authentication
Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.
Improper Handling of Case Sensitivity vulnerability in Drupal External Authentication allows Privilege Escalation. This issue affects External Authentication versions: from 0.0.0 to 2.0.13.
Affected products
- External Authentication Project External Authentication: before 2.0.13 (fixed in 2.0.13); from 8.x-1.0, up to and including 8.x-1.4
Published 2026-09-02. Last modified 2026-09-15.