PT-2026-94355 · Unknown · Ashauthentication
CVSS v4.0
9.1
Critical
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
ash authentication versions 4.14.0 through 4.14.x
ash authentication versions 5.0.0-rc.10 through 5.0.0-rc.13
Description
An improper authentication issue allows an attacker to sign in as another user by linking an OAuth2 identity to an account that does not belong to them. The
AshAuthentication.Strategy.OAuth2.UserResolver.resolve/3 function matches an existing account using upsert identity keys and validates the link via email trusted?/2. However, this check only verifies the provider's email verified boolean and fails to compare the provider's email value with the matched account's email. This flaw also exists in OAuth2.SignInPreparation when registration enabled? is false and the account is matched by the sign-in action's read filter. An attacker with a verified email from a provider can be issued a session for an account matched on a different attribute. Additionally, the process rewrites the matched account's email to the attacker's address, allowing the attacker to intercept future account recovery attempts.Recommendations
Update ash authentication to version 4.15.0 or later.
Update ash authentication to version 5.0.0-rc.14 or later.
Set
trust email verified? to false on the affected strategy to refuse the sign-in.
Configure the register action's upsert identity or the sign-in action's read filter to use the email attribute.Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ashauthentication