PT-2026-95162 · Unknown · Ashauthentication

·

CVE-2026-86688

·

Published

2026-09-17

·

Updated

2026-09-17

CVSS v4.0

7.4

High

VectorAV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions ash authentication versions 0.2.0 through 4.14.9 ash authentication versions 5.0.0-rc.0 through 5.0.0-rc.13
Description A session fixation issue allows an attacker to maintain an authenticated session if they can plant a session identifier in a victim's browser before the victim signs in. This occurs because the function store in session/2 in AshAuthentication.Plug.Helpers uses Plug.Conn.put session/3 to write the authenticated subject without calling Plug.Conn.configure session(renew: true), causing the pre-authentication identifier to persist. This affects the default success/4 function in AshAuthentication.Phoenix.Controller. using /1, the AuthController from mix ash authentication phoenix.install, and remember-me auto-login. Additionally, the clear session/2 function uses Plug.Conn.clear session/1, which removes session content but keeps the identifier, allowing a planted ID to survive a logout-then-login sequence. In deployments using server-side session stores (such as ETS, Mnesia, Redis, or a database), this can lead to full account takeover. This is possible if the attacker can plant a cookie via sibling subdomain cookie tossing, an HTTP host without HSTS, or a shared browser.
Recommendations Update ash authentication to version 4.15.0 or later. Update ash authentication to version 5.0.0-rc.14 or later. As a temporary workaround, call Plug.Conn.configure session(conn, renew: true) within the success/4 function before store in session/2 is called. As a temporary workaround, add Plug.Conn.configure session(conn, drop: true) during the sign-out process to ensure planted identifiers are removed.

Exploit

Fix

Session Fixation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-86688
GHSA-V577-944G-7H3X

Affected Products

Ashauthentication