CVE-2026-47203: low-severity vulnerability in authelia
Authelia Missing Username Canonicalization in Basic Auth (LDAP)
Published · Updated
8Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 2.9epss 0.5%
exploitation probability
0.5%top 63% of all CVEs
observed exploitation
nono source reports it
Authelia is an open-source authentication and authorization server providing two-factor authentication and single sign-on (SSO) for applications via a web portal. In versions 4.38.0 through 4.39.19, when a user authenticates via Basic Auth (i.e via the `Authorization` header with the `Basic` scheme) on the authz verification endpoint, Authelia takes the username directly from the `Authorization` header and passes it as is to the regulation system for ban checking and attempt recording. LDAP treats usernames case insensitively : `john`, `John`, and `JOHN` all bind as the same user. But the regulation SQL queries treat the lookup of these values in certain scenarios as case sensitive. This allows each variation of a usernames case to have its own ban bucket. Upgrade to 4.39.20 to receive a patch. As a workaround, explicitly disable the basic auth mechanism.
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P
Affected products
authelia · autheliaRelated CVEs — authelia
In the same product, most dangerous first.
CVE-2021-32637CRITICALAuthentication bypassed with malformed request URIEPSS 1.9%CVE-2021-29456MEDIUMAuthelia allows open redirects on the logout endpointEPSS 0.5%CVE-2026-48794LOWAuthelia has an Edge Case Access Control Rule MismatchEPSS 0.4%CVE-2025-24806LOWRegulation applies separately to Username-based logins to Email-based logins in autheliaEPSS 0.4%CVE-2026-33525LOWAuthelia: Improper Neutralization of Input During Web Page Generation Leads to Potential Cross-site ScriptingEPSS 0.3%