PT-2026-94294 · Unknown · Ashauthentication

·

CVE-2026-82685

·

Published

2026-09-17

·

Updated

2026-09-17

CVSS v4.0

7.6

High

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions ash authentication versions 0.5.0 through 4.14.9 ash authentication versions 5.0.0-rc.0 through 5.0.0-rc.13
Description An authorization bypass allows an authenticated attacker to overwrite and confirm another user's email address to take over their account. This occurs because a confirmation token issued to one user is accepted on any other user's record. Specifically, the AshAuthentication.AddOn.Confirmation.ConfirmChange function verifies the token's signature and its act claim but fails to compare the sub claim against changeset.data before applying changes to the target record. An attacker can register an account, change their own email, and replay the resulting token against a victim's record ID using force change attributes/2 to set their own address and stamp confirmed at, subsequently gaining access via a password reset. The confirmation flow using AshAuthentication.AddOn.Confirmation.Actions.confirm/3 is not affected as it correctly resolves sub to a user.
Recommendations Update ash authentication to version 4.15.0 or later. Update ash authentication to version 5.0.0-rc.14 or later.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82685
GHSA-G636-26VF-2W63

Affected Products

Ashauthentication