PT-2026-49202 · Unknown · Ashauthentication

·

CVE-2026-49757

·

Published

2026-06-15

·

Updated

2026-08-25

CVSS v4.0

9.2

Critical

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions ash authentication versions 0.1.0 through 4.13.x ash authentication versions 5.0.0-rc.0 through 5.0.0-rc.9
Description An authentication bypass by spoofing allows account takeover of local users during OAuth2 or OIDC sign-in. The issue occurs because the software matches local users by email address instead of using the OpenID Connect iss (issuer) and sub (subject) claim combination, which are the only stable and unique identifiers for an end-user. An unauthenticated attacker can register an account on an accepted OAuth provider using a victim's email—including unverified or reused emails—to gain full local privileges of the victim's account.
Recommendations Update versions 0.1.0 through 4.13.x to version 4.14.0. Update versions 5.0.0-rc.0 through 5.0.0-rc.9 to version 5.0.0-rc.10.

Exploit

Fix

Authentication Bypass by Spoofing

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-49757
GHSA-777C-2FXX-QR28

Affected Products

Ashauthentication