PT-2026-94299 · Unknown · Ashauthentication

·

CVE-2026-85500

·

Published

2026-09-17

·

Updated

2026-09-17

CVSS v4.0

9.1

Critical

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions ash authentication versions 4.3.8 through 4.14.9 ash authentication versions 5.0.0-rc.0 through 5.0.0-rc.13
Description An authentication bypass allows unconfirmed users to obtain a session, bypassing mandatory email confirmation requirements. The issue occurs in the check user/2 function within AshAuthentication.Strategy.Password.Actions, which uses is nil(Map.get(user, value)) to verify the attribute specified by require confirmed with. If the attribute is not selected or denied by a field policy, Map.get/2 returns %Ash.NotLoaded{} or %Ash.ForbiddenField{} instead of nil, causing the system to incorrectly treat the user as confirmed.
Additionally, the require confirmed with check is only performed within AshAuthentication.Strategy.Password.Actions and not on the actions themselves. Consequently, callers that invoke actions directly, such as AshGraphql or AshJsonApi, skip the confirmation check entirely in default configurations.
Recommendations Update ash authentication to version 4.15.0 or later. Update ash authentication to version 5.0.0-rc.14 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-85500
GHSA-FC47-6PGW-WH22

Affected Products

Ashauthentication