HTTP Request Vulnerability in AshAuthenticationPhoenix by Team Alembic
CVE-2026-81632
Key Information:
- Vendor
Team-alembic
- Vendor
- CVE Published:
- 17 September 2026
What is CVE-2026-81632?
The AshAuthenticationPhoenix product by Team Alembic is susceptible to a vulnerability where sensitive data, specifically a single-use sign-in token, is transmitted via an HTTP request. This occurs post-password sign-in, where the application's sign-in mechanism improperly includes the user token as a query parameter in the URL. Consequently, the token can be captured from various logs—such as web server logs, proxy logs, or the browser's own history—exposing users to potential unauthorized access. While the redirect is limited to a local path, the unprotected state of the token in transit poses a significant risk, compromising the integrity of user authentication.
Affected Version(s)
ash_authentication 3.10.5 < 4.15.0
ash_authentication 5.0.0-rc.0 < 5.0.0-rc.14
ash_authentication eca8cadea0f1595ed2c10a0c177b1da9aa9e5269
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
