PT-2026-94298 · Unknown · Ashauthentication

·

CVE-2026-82761

·

Published

2026-09-17

·

Updated

2026-09-17

CVSS v4.0

9.1

Critical

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions ash authentication versions 3.9.0 through 4.14.9 ash authentication versions 5.0.0-rc.0 through 5.0.0-rc.13
Description A Time-of-check Time-of-use (TOCTOU) Race Condition occurs when a magic link is configured with single use token?. This allows an attacker with a leaked magic link to replay a single-use token and authenticate as the target subject. The issue arises because the token validity check is not serialized against its consumption, allowing concurrent redemptions to succeed and yield full user tokens. The sign-in process verifies the JWT using Jwt.verify/4 and revokes it subsequently via AshAuthentication.Strategy.MagicLink.SignInPreparation in a Query.after action callback and AshAuthentication.Strategy.MagicLink.SignInChange in an after transaction hook. Because AshAuthentication.TokenResource.Actions.revoke/3 performs the revocation as an upsert, concurrent duplicate revocations succeed without conflict.
Recommendations Update ash authentication to version 4.15.0 or later. Update ash authentication to version 5.0.0-rc.14 or later.

Exploit

Fix

Time Of Check To Time Of Use

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82761
GHSA-23GR-VCP4-R27Q

Affected Products

Ashauthentication