PT-2026-94355 · Unknown · Ashauthentication

·

CVE-2026-88952

·

Published

2026-09-17

·

Updated

2026-09-17

CVSS v4.0

9.1

Critical

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions ash authentication versions 4.14.0 through 4.14.x ash authentication versions 5.0.0-rc.10 through 5.0.0-rc.13
Description An improper authentication issue allows an attacker to sign in as another user by linking an OAuth2 identity to an account that does not belong to them. The AshAuthentication.Strategy.OAuth2.UserResolver.resolve/3 function matches an existing account using upsert identity keys and validates the link via email trusted?/2. However, this check only verifies the provider's email verified boolean and fails to compare the provider's email value with the matched account's email. This flaw also exists in OAuth2.SignInPreparation when registration enabled? is false and the account is matched by the sign-in action's read filter. An attacker with a verified email from a provider can be issued a session for an account matched on a different attribute. Additionally, the process rewrites the matched account's email to the attacker's address, allowing the attacker to intercept future account recovery attempts.
Recommendations Update ash authentication to version 4.15.0 or later. Update ash authentication to version 5.0.0-rc.14 or later. Set trust email verified? to false on the affected strategy to refuse the sign-in. Configure the register action's upsert identity or the sign-in action's read filter to use the email attribute.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-88952
GHSA-WC6X-276Q-JRF9

Affected Products

Ashauthentication