Insufficient Session Expiration in AshAuthentication by Team Alembic
CVE-2026-81637

2.3LOW

Key Information:

Vendor
CVE Published:
17 September 2026

What is CVE-2026-81637?

An insufficient session expiration vulnerability in AshAuthentication enables attackers to exploit an OAuth2 state value, allowing them to replay the callback and sign the victim into a maliciously controlled account. This occurs because the session parameters are not cleared effectively on failure paths of the authentication process, allowing sensitive data to persist beyond intended usage. Versions from ash_authentication 0.6.0 up to but not including 4.15.0, and versions from 5.0.0-rc.0 to below 5.0.0-rc.14 are affected. Developers are encouraged to review security patches and ensure robust session management to mitigate risks.

Affected Version(s)

ash_authentication 0.6.0 < 4.15.0

ash_authentication 5.0.0-rc.0 < 5.0.0-rc.14

ash_authentication c5f589058e04239263f50a1430eb17ea6d5dd1a2

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peter Ullrich
Jonatan Männchen / EEF
James Harton
.