SA-CONTRIB-2026-098: Critical severity drupal/externalauth vulnerability
This module enables you to authenticate Drupal users against external identity providers. The module does not sufficiently ensure exact matching of externally supplied identity values when storing and looking up authentication mappings under certain database collation configurations. This vulnerability is mitigated by the fact that it affects only sites using impacted MySQL or MariaDB collation settings for the module’s authentication mapping storage.
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
drupal/externalauthto a version that resolves this vulnerability.Fixed in 2.0.13
Event History
Frequently Asked Questions
What is the severity of SA-CONTRIB-2026-098?
The severity of SA-CONTRIB-2026-098 is critical, rated at 9.
How do I fix SA-CONTRIB-2026-098?
To fix SA-CONTRIB-2026-098, update the Drupal externalauth module to the latest version that addresses this vulnerability.
What kind of vulnerability is SA-CONTRIB-2026-098?
SA-CONTRIB-2026-098 is an authentication bypass vulnerability that affects users authenticating against external identity providers.
What are the potential impacts of SA-CONTRIB-2026-098?
The potential impacts of SA-CONTRIB-2026-098 include unauthorized access to user accounts and compromised user data.
Is my Drupal site at risk if I use the externalauth module affected by SA-CONTRIB-2026-098?
Yes, if your Drupal site uses the externalauth module without applying the necessary security updates, it is at risk from SA-CONTRIB-2026-098.