PT-2026-94285 · Unknown · Ashauthentication

·

CVE-2026-78223

·

Published

2026-09-17

·

Updated

2026-09-17

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions ash authentication versions 0.2.0 through 4.14.9 ash authentication versions 5.0.0-rc.0 through 5.0.0-rc.13
Description Improper verification of cryptographic signatures in AshAuthentication allows a caller of the token revocation action to neutralize a revocation or write arbitrary rows into the token resource. The function AshAuthentication.TokenResource.RevokeTokenChange.change/3 reads the :token argument and decodes it using AshAuthentication.Jwt.peek/1, which delegates to Joken.peek claims/1 without performing a signature check. Consequently, the jti, exp, and sub claims are written directly to the revocation record. An attacker can provide a forged token with a backdated exp claim, causing the revocation row to be treated as expired and removed by expunge expired, which allows the genuine token to pass the revoked? check. Additionally, arbitrary jti and sub values can be inserted into the resource.
Recommendations Update ash authentication to version 4.15.0 or later. Update ash authentication to version 5.0.0-rc.14 or later.

Exploit

Fix

Improper Verification of Cryptographic Signature

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-78223
GHSA-MFWG-5CPF-PX58

Affected Products

Ashauthentication