Authentication Bypass Vulnerability in AshAuthentication by team-alembic
CVE-2026-49757

9.2CRITICAL

Key Information:

Vendor
CVE Published:
15 June 2026

What is CVE-2026-49757?

An authentication bypass vulnerability exists in AshAuthentication that allows attackers to take over local user accounts via OAuth2 or OIDC sign-ins. The flaw arises from a reliance on email addresses for user identification instead of the recommended OpenID Connect iss/sub claims. This means an unauthenticated attacker can exploit the vulnerability by registering with a victim's email on any authorized OAuth provider. Once done, they can gain full access to the victim's local account privileges if the provider's email is unverified or reused. A security update has been introduced to rectify the issue by ensuring that user identities are linked only when trusted conditions, such as verified emails, are met.

Affected Version(s)

ash_authentication 0.1.0 < 4.14.0

ash_authentication 5.0.0-rc.0 < 5.0.0-rc.10

ash_authentication c5f589058e04239263f50a1430eb17ea6d5dd1a2

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jarl André Hübenthal
James Harton
Jonatan Männchen / EEF
.