HTTP Request Vulnerability in AshAuthenticationPhoenix by Team Alembic
CVE-2026-81632

7.2HIGH

What is CVE-2026-81632?

The AshAuthenticationPhoenix product by Team Alembic is susceptible to a vulnerability where sensitive data, specifically a single-use sign-in token, is transmitted via an HTTP request. This occurs post-password sign-in, where the application's sign-in mechanism improperly includes the user token as a query parameter in the URL. Consequently, the token can be captured from various logs—such as web server logs, proxy logs, or the browser's own history—exposing users to potential unauthorized access. While the redirect is limited to a local path, the unprotected state of the token in transit poses a significant risk, compromising the integrity of user authentication.

Affected Version(s)

ash_authentication 3.10.5 < 4.15.0

ash_authentication 5.0.0-rc.0 < 5.0.0-rc.14

ash_authentication eca8cadea0f1595ed2c10a0c177b1da9aa9e5269

References

CVSS V4

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peter Ullrich
Jonatan Männchen / EEF
James Harton
.