PT-2026-94373 · Unknown · Ashauthentication

·

CVE-2026-91039

·

Published

2026-09-17

·

Updated

2026-09-17

CVSS v4.0

9.1

Critical

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions ash authentication versions 5.0.0-rc.10 through 5.0.0-rc.13
Description An authentication bypass by spoofing exists in the dynamic oidc strategy. This allows an attacker using one identity-provider connection to be signed in as a local user associated with a different connection. The issue occurs because the intended identity namespacing, which should format the strategy field of UserIdentity rows as "<name>/<connection id>", is not applied. Instead, the connection id variable is only populated on an ephemeral runtime struct and is not used during the identity change process in the DynamicOidc.IdentityChange.change/3 function. Consequently, the system falls back to the bare strategy name for identity writes and reads in oauth2/user resolver.ex and oauth2/sign in preparation.ex.
Because the unique key for the identity resource is (uid, strategy) and the system does not handle the iss (issuer) claim, users from different providers with the same sub (subject) value are treated as the same user. This can lead to account takeover without victim interaction or the silent merging of distinct users who happen to share the same subject identifier across different providers.
Recommendations For versions 5.0.0-rc.10 through 5.0.0-rc.13, update the software to version 5.0.0-rc.14 or later. After updating, each UserIdentity row's strategy field must be manually relinked to the "<name>/<connection id>" format to ensure existing identities match the new namespacing logic. For deployments using more than one connection, perform an out-of-band audit by exporting sub values from each identity provider and intersecting them to identify and resolve accounts that may have been merged.

Exploit

Fix

Authentication Bypass by Spoofing

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-91039
GHSA-73J9-M294-FVV9

Affected Products

Ashauthentication