CVE-2026-47203: fallo de gravedad baja en authelia
Authelia Missing Username Canonicalization in Basic Auth (LDAP)
Publicada el · Actualizada el
8Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 2.9epss 0.5%
probabilidad de explotación
0.5%top 63% de las CVE
explotación observada
noninguna fuente lo reporta
Authelia is an open-source authentication and authorization server providing two-factor authentication and single sign-on (SSO) for applications via a web portal. In versions 4.38.0 through 4.39.19, when a user authenticates via Basic Auth (i.e via the `Authorization` header with the `Basic` scheme) on the authz verification endpoint, Authelia takes the username directly from the `Authorization` header and passes it as is to the regulation system for ban checking and attempt recording. LDAP treats usernames case insensitively : `john`, `John`, and `JOHN` all bind as the same user. But the regulation SQL queries treat the lookup of these values in certain scenarios as case sensitive. This allows each variation of a usernames case to have its own ban bucket. Upgrade to 4.39.20 to receive a patch. As a workaround, explicitly disable the basic auth mechanism.
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P
Productos afectados
authelia · autheliaCVEs relacionadas — authelia
En el mismo producto, de las más peligrosas a las menos.
CVE-2021-32637CRITICALAuthentication bypassed with malformed request URIEPSS 1.9%CVE-2021-29456MEDIUMAuthelia allows open redirects on the logout endpointEPSS 0.5%CVE-2026-48794LOWAuthelia has an Edge Case Access Control Rule MismatchEPSS 0.4%CVE-2025-24806LOWRegulation applies separately to Username-based logins to Email-based logins in autheliaEPSS 0.4%CVE-2026-33525LOWAuthelia: Improper Neutralization of Input During Web Page Generation Leads to Potential Cross-site ScriptingEPSS 0.3%