PT-2026-94373 · Unknown · Ashauthentication
CVSS v4.0
9.1
Critical
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
ash authentication versions 5.0.0-rc.10 through 5.0.0-rc.13
Description
An authentication bypass by spoofing exists in the
dynamic oidc strategy. This allows an attacker using one identity-provider connection to be signed in as a local user associated with a different connection. The issue occurs because the intended identity namespacing, which should format the strategy field of UserIdentity rows as "<name>/<connection id>", is not applied. Instead, the connection id variable is only populated on an ephemeral runtime struct and is not used during the identity change process in the DynamicOidc.IdentityChange.change/3 function. Consequently, the system falls back to the bare strategy name for identity writes and reads in oauth2/user resolver.ex and oauth2/sign in preparation.ex.Because the unique key for the identity resource is
(uid, strategy) and the system does not handle the iss (issuer) claim, users from different providers with the same sub (subject) value are treated as the same user. This can lead to account takeover without victim interaction or the silent merging of distinct users who happen to share the same subject identifier across different providers.Recommendations
For versions 5.0.0-rc.10 through 5.0.0-rc.13, update the software to version 5.0.0-rc.14 or later. After updating, each
UserIdentity row's strategy field must be manually relinked to the "<name>/<connection id>" format to ensure existing identities match the new namespacing logic.
For deployments using more than one connection, perform an out-of-band audit by exporting sub values from each identity provider and intersecting them to identify and resolve accounts that may have been merged.Exploit
Fix
Authentication Bypass by Spoofing
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ashauthentication