PT-2026-94295 · Unknown · Ashauthentication

·

CVE-2026-82723

·

Published

2026-09-17

·

Updated

2026-09-17

CVSS v4.0

1.8

Low

VectorAV:L/AC:H/AT:P/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions ash authentication versions 4.12.0 through 4.14.x ash authentication versions 5.0.0-rc.0 through 5.0.0-rc.1
Description AshAuthentication allows the disclosure of user password digests to readers of the audit store. The audit log add-on builds extra data for each entry in the AshAuthentication.AddOn.AuditLog.Auditor.build extra data/4 function, which takes the :actor from the action callback context verbatim. When an audited action is invoked with actor: set to a user record, the record—including the hashed password attribute—is deposited into the audit entry. While other identities are collapsed via AshAuthentication.user to subject/1 and parameters are filtered, the actor remains unfiltered. Setting the attribute sensitive?: true is ineffective as it only redacts inspect/1 output and not JSON encoding or raw-term storage. Exploitation requires independent read access to the audit store (e.g., database credentials, backups, or log shippers), enabling offline password attacks against active accounts. Persistence of this data depends on the data layer; raw-term stores keep it verbatim, whereas SQL stores may drop the entry unless the user resource derives Jason.Encoder.
Recommendations Update ash authentication to version 4.15.0 or later. Update ash authentication to version 5.0.0-rc.2 or later.

Exploit

Fix

Insertion into Log File

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82723
GHSA-59WX-Q3R8-GHV4

Affected Products

Ashauthentication