Authorization Bypass Vulnerability in AshAuthentication by Team Alembic
CVE-2026-82685

7.6HIGH

Key Information:

Vendor
CVE Published:
17 September 2026

What is CVE-2026-82685?

An authorization bypass vulnerability in Team Alembic's AshAuthentication allows authenticated users to exploit a flaw in the email confirmation mechanism. This security issue enables an attacker to use a confirmation token generated for their account to overwrite the email address associated with another user's account. By doing so, the attacker can gain control over the victim's account, potentially facilitating unauthorized access. The vulnerability arises from the system's insufficient verification of the token against the intended user's record during the confirmation process, resulting in multiple accounts being susceptible. This issue is present in specific versions of the AshAuthentication library and requires immediate attention from users and administrators to implement security patches.

Affected Version(s)

ash_authentication 0.5.0 < 4.15.0

ash_authentication 5.0.0-rc.0 < 5.0.0-rc.14

ash_authentication 1d4bb00617aecae85c33f2ff5bc7e094c6449a6e

References

CVSS V4

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peter Ullrich
James Harton
Jonatan Männchen / EEF
.