Eqstlab

#1613of 56,330
147.4Total CVSS
Vulnerabilities · 18
Medium
1
High
14
Critical
3
PT-2026-81202
7.6
2026-08-25
Unknown · Ashauthentication · CVE-2026-65633
**Name of the Vulnerable Software and Affected Versions** ash authentication versions 3.10.5 through 4.14.1 ash authentication versions 5.0.0-rc.0 through 5.0.0-rc.12 **Description** Improper authentication allows purpose-limited JSON Web Tokens (JWTs) to be replayed as full bearer API credentials when a resource uses stateless bearer-token verification. The helper function `retrieve from bearer/3` verifies the signature of an Authorization: Bearer JWT and rejects tokens with an `act` claim, but fails to verify if the token's `purpose` claim equals `user`. When the resource is configured with `require token presence for authentication?` set to `false`, the `validate token/3` helper returns `{:ok, nil}` without consulting the token resource, bypassing downstream purpose checks. Consequently, valid, non-expired JWTs issued for narrow purposes—such as the `sign in` token emitted by WebAuthn or the Password strategy—are accepted as general-purpose bearer credentials, granting full `current user` assignment. An attacker who obtains a valid `sign in` token can authenticate as the target subject, bypassing one-time-use and revocation semantics. This requires the application to use `retrieve from bearer/3` on a reachable route and employ either WebAuthn or the Password strategy with `sign in tokens enabled?` set to `true`. **Recommendations** Update ash authentication to version 4.14.2 or later. Update ash authentication to version 5.0.0-rc.13 or later. Set `require token presence for authentication?` to `true` to enforce purpose verification against the stored token record. Restrict access to routes utilizing the `retrieve from bearer/3` helper function.