PT-2026-94300 · Unknown · Ashauthentication

·

CVE-2026-86522

·

Published

2026-09-17

·

Updated

2026-09-17

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions ash authentication versions 4.2.0 through 4.14.9 ash authentication versions 5.0.0-rc.0 through 5.0.0-rc.13
Description An unauthenticated attacker can forge application log entries by submitting a password reset identity containing newlines or control characters. The function AshAuthentication.Strategy.Password.RequestPasswordReset.run/3 interpolates the identity variable, which contains the email or username from the reset request, into Logger.warning/1 heredocs without escaping, truncating, or type-restricting it. Because a newline in the identity variable ends the log record, any subsequent text is written as a new line, allowing an attacker to manipulate the severity tag and the content of entries to make them appear as if they originated from the application.
Recommendations Update ash authentication to version 4.15.0 or later. Update ash authentication to version 5.0.0-rc.14 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-86522
GHSA-WG7G-R393-VR3G

Affected Products

Ashauthentication