DRUPAL-CONTRIB-2026-098

See a problem?
Import Source
https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/externalauth/DRUPAL-CONTRIB-2026-098.json
JSON Data
https://api.osv.dev/v1/vulns/DRUPAL-CONTRIB-2026-098
Aliases
  • CVE-2026-73476
Published
2026-08-12T17:56:03Z
Modified
2026-08-12T19:45:03.162049412Z
Summary
[none]
Details

This module enables you to authenticate Drupal users against external identity providers.
The module does not sufficiently ensure exact matching of externally supplied identity values when storing and looking up authentication mappings under certain database collation configurations.
This vulnerability is mitigated by the fact that it affects only sites using impacted MySQL or MariaDB collation settings for the module’s authentication mapping storage.

References
Credits

Affected packages

Packagist:https://packages.drupal.org/8 / drupal/externalauth

Package

Name
drupal/externalauth
Purl
pkg:composer/drupal/externalauth?repository_url=https:%2F%2Fpackages.drupal.org%2F8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.0.13
Database specific
Show details
{
    "constraint": "<2.0.13"
}

Database specific

affected_versions
"<2.0.13"
source
"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/externalauth/DRUPAL-CONTRIB-2026-098.json"