PT-2026-94289 · Unknown · Ashauthentication
CVSS v4.0
7.6
High
| Vector | AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
ash authentication versions 3.10.5 through 4.14.9
ash authentication versions 5.0.0-rc.0 through 5.0.0-rc.13
Description
Improper authentication allows an attacker with a sign-in token for one authenticated resource to be signed in as a user of a different resource. The function
extract primary keys from subject/2 within AshAuthentication.Strategy.Password.SignInWithTokenPreparation parses the JWT sub claim using URI.parse/1 and retains only the query string, discarding the path segment that identifies the subject for which the token was issued. Because AshAuthentication.Jwt.verify/3 only validates the signature and specific claims (exp, nbf, jti, and library-version) without restoring the resource binding, and primary-key field names are identical across resources, the authentication is bypassed. This behavior also affects WebAuthn sign-in and remember-me preparations. The magic link sign-in path is not affected.Recommendations
Update ash authentication to version 4.15.0 or later.
Update ash authentication to version 5.0.0-rc.14 or later.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ashauthentication