View online: https://www.drupal.org/sa-contrib-2026-098 Project: External Authentication [1] Date: 2026-August-12 Security risk: *Moderately critical* 13 ∕ 25 AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:Default [2] Vulnerability: Access bypass Affected versions: <2.0.13 CVE IDs: CVE-2026-73476 Description: This module enables you to authenticate Drupal users against external identity providers. The module does not sufficiently ensure exact matching of externally supplied identity values when storing and looking up authentication mappings under certain database collation configurations. This vulnerability is mitigated by the fact that it affects only sites using impacted MySQL or MariaDB collation settings for the module’s authentication mapping storage. Solution: Install the latest version: * If you use the externalauth module for Drupal, upgrade to 2.0.13 [3] Reported By: * 晉宇 林 (whale120) [4] Fixed By: * Sven Decabooter (svendecabooter) [5] Coordinated By: * Swan Kalata (akalata) [6] of the Drupal Security Team * Neil Drumm (drumm) [7] of the Drupal Security Team * Greg Knaddison (greggles) [8] of the Drupal Security Team * Juraj Nemec (poker10) [9] of the Drupal Security Team ------------------------------------------------------------------------------ Contribution record [10] [1] https://www.drupal.org/project/externalauth [2] https://www.drupal.org/security-team/risk-levels [3] https://www.drupal.org/project/externalauth/releases/2.0.13 [4] https://www.drupal.org/u/whale120 [5] https://www.drupal.org/u/svendecabooter [6] https://www.drupal.org/u/akalata [7] https://www.drupal.org/u/drumm [8] https://www.drupal.org/u/greggles [9] https://www.drupal.org/u/poker10 [10] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal....