PT-2026-94294 · Unknown · Ashauthentication
CVSS v4.0
7.6
High
| Vector | AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
ash authentication versions 0.5.0 through 4.14.9
ash authentication versions 5.0.0-rc.0 through 5.0.0-rc.13
Description
An authorization bypass allows an authenticated attacker to overwrite and confirm another user's email address to take over their account. This occurs because a confirmation token issued to one user is accepted on any other user's record. Specifically, the
AshAuthentication.AddOn.Confirmation.ConfirmChange function verifies the token's signature and its act claim but fails to compare the sub claim against changeset.data before applying changes to the target record. An attacker can register an account, change their own email, and replay the resulting token against a victim's record ID using force change attributes/2 to set their own address and stamp confirmed at, subsequently gaining access via a password reset. The confirmation flow using AshAuthentication.AddOn.Confirmation.Actions.confirm/3 is not affected as it correctly resolves sub to a user.Recommendations
Update ash authentication to version 4.15.0 or later.
Update ash authentication to version 5.0.0-rc.14 or later.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ashauthentication