PT-2026-94289 · Unknown · Ashauthentication

·

CVE-2026-80218

·

Published

2026-09-17

·

Updated

2026-09-17

CVSS v4.0

7.6

High

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions ash authentication versions 3.10.5 through 4.14.9 ash authentication versions 5.0.0-rc.0 through 5.0.0-rc.13
Description Improper authentication allows an attacker with a sign-in token for one authenticated resource to be signed in as a user of a different resource. The function extract primary keys from subject/2 within AshAuthentication.Strategy.Password.SignInWithTokenPreparation parses the JWT sub claim using URI.parse/1 and retains only the query string, discarding the path segment that identifies the subject for which the token was issued. Because AshAuthentication.Jwt.verify/3 only validates the signature and specific claims (exp, nbf, jti, and library-version) without restoring the resource binding, and primary-key field names are identical across resources, the authentication is bypassed. This behavior also affects WebAuthn sign-in and remember-me preparations. The magic link sign-in path is not affected.
Recommendations Update ash authentication to version 4.15.0 or later. Update ash authentication to version 5.0.0-rc.14 or later.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-80218
GHSA-3PR8-F99Q-86HP

Affected Products

Ashauthentication