Unknown · Ashauthentication · CVE-2026-91039
**Name of the Vulnerable Software and Affected Versions**
ash authentication versions 5.0.0-rc.10 through 5.0.0-rc.13
**Description**
An authentication bypass by spoofing exists in the `dynamic oidc` strategy. This allows an attacker using one identity-provider connection to be signed in as a local user associated with a different connection. The issue occurs because the intended identity namespacing, which should format the `strategy` field of `UserIdentity` rows as `"<name>/<connection id>"`, is not applied. Instead, the ` connection id ` variable is only populated on an ephemeral runtime struct and is not used during the identity change process in the `DynamicOidc.IdentityChange.change/3` function. Consequently, the system falls back to the bare strategy name for identity writes and reads in `oauth2/user resolver.ex` and `oauth2/sign in preparation.ex`.
Because the unique key for the identity resource is `(uid, strategy)` and the system does not handle the `iss` (issuer) claim, users from different providers with the same `sub` (subject) value are treated as the same user. This can lead to account takeover without victim interaction or the silent merging of distinct users who happen to share the same subject identifier across different providers.
**Recommendations**
For versions 5.0.0-rc.10 through 5.0.0-rc.13, update the software to version 5.0.0-rc.14 or later. After updating, each `UserIdentity` row's `strategy` field must be manually relinked to the `"<name>/<connection id>"` format to ensure existing identities match the new namespacing logic.
For deployments using more than one connection, perform an out-of-band audit by exporting `sub` values from each identity provider and intersecting them to identify and resolve accounts that may have been merged.