Authentication Bypass Vulnerability in AshAuthentication by team-alembic
CVE-2026-49757
What is CVE-2026-49757?
An authentication bypass vulnerability exists in AshAuthentication that allows attackers to take over local user accounts via OAuth2 or OIDC sign-ins. The flaw arises from a reliance on email addresses for user identification instead of the recommended OpenID Connect iss/sub claims. This means an unauthenticated attacker can exploit the vulnerability by registering with a victim's email on any authorized OAuth provider. Once done, they can gain full access to the victim's local account privileges if the provider's email is unverified or reused. A security update has been introduced to rectify the issue by ensuring that user identities are linked only when trusted conditions, such as verified emails, are met.
Affected Version(s)
ash_authentication 0.1.0 < 4.14.0
ash_authentication 5.0.0-rc.0 < 5.0.0-rc.10
ash_authentication c5f589058e04239263f50a1430eb17ea6d5dd1a2
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
