PT-2026-94292 · Unknown · Ashauthentication+1

·

CVE-2026-81632

·

Published

2026-09-17

·

Updated

2026-09-17

CVSS v4.0

7.2

High

VectorAV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions ash authentication phoenix versions 1.7.0 through 2.17.3 ash authentication phoenix versions 3.0.0-rc.0 through 3.0.0-rc.10 ash authentication versions 3.10.5 through 4.14.9 ash authentication versions 5.0.0-rc.0 through 5.0.0-rc.13
Description An issue in AshAuthenticationPhoenix allows an attacker with access to access logs, proxy logs, or browser history to recover a single-use sign-in token and authenticate as the token owner. This occurs because AshAuthentication.Phoenix.Components.Password.SignInForm constructs the sign in with token path using the user. metadata .token as a query parameter and performs a GET redirect. Consequently, the token is recorded in the request line by web servers, reverse proxies, and browser history, exposing a live credential in locations that are typically less secure than session storage.
Recommendations Update ash authentication phoenix to version 2.17.4 or later. Update ash authentication phoenix to version 3.0.0-rc.11 or later. Update ash authentication to version 4.15.0 or later. Update ash authentication to version 5.0.0-rc.14 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-81632
GHSA-8JH5-339H-MQX9
GHSA-J726-59HM-R46R

Affected Products

Ashauthentication
Ash Authentication Phoenix