PT-2026-94299 · Unknown · Ashauthentication
CVSS v4.0
9.1
Critical
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
ash authentication versions 4.3.8 through 4.14.9
ash authentication versions 5.0.0-rc.0 through 5.0.0-rc.13
Description
An authentication bypass allows unconfirmed users to obtain a session, bypassing mandatory email confirmation requirements. The issue occurs in the
check user/2 function within AshAuthentication.Strategy.Password.Actions, which uses is nil(Map.get(user, value)) to verify the attribute specified by require confirmed with. If the attribute is not selected or denied by a field policy, Map.get/2 returns %Ash.NotLoaded{} or %Ash.ForbiddenField{} instead of nil, causing the system to incorrectly treat the user as confirmed.Additionally, the
require confirmed with check is only performed within AshAuthentication.Strategy.Password.Actions and not on the actions themselves. Consequently, callers that invoke actions directly, such as AshGraphql or AshJsonApi, skip the confirmation check entirely in default configurations.Recommendations
Update ash authentication to version 4.15.0 or later.
Update ash authentication to version 5.0.0-rc.14 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ashauthentication