PT-2026-94301 · Unknown+1 · Ashauthentication+1

·

CVE-2026-86533

·

Published

2026-09-17

·

Updated

2026-09-17

CVSS v4.0

9.1

Critical

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions ash authentication versions 4.9.1 through 4.14.9 ash authentication versions 5.0.0-rc.0 through 5.0.0-rc.13 ash authentication phoenix versions 2.10.0 through 2.17.3 ash authentication phoenix versions 3.0.0-rc.0 through 3.0.0-rc.10
Description Insufficient session expiration allows a revoked session to remain fully authenticated. When a resource is configured with session identifier :jti and require token presence for authentication? is disabled, the session value is stored as <jti>:<subject>. The functions AshAuthentication.Plug.Helpers.authenticate resource from session/4 and AshAuthentication.Phoenix.LiveSession.on mount/4 use split identifier/2 to discard the jti and pass only the subject to AshAuthentication.subject to user/3. Since the revocation record is not consulted, the revoked state and expiry of the jti are ignored, allowing sessions captured before sign-out to remain active.
Recommendations Update ash authentication to version 4.15.0 or later. Update ash authentication to version 5.0.0-rc.14 or later. Update ash authentication phoenix to version 2.17.4 or later. Update ash authentication phoenix to version 3.0.0-rc.11 or later.

Exploit

Fix

Insufficient Session Expiration

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-86533
GHSA-M6X4-4GVP-XWJR
GHSA-W374-HVRX-66HG

Affected Products

Ashauthentication
Ash Authentication Phoenix