Authorization Bypass Vulnerability in AshAuthentication by Team Alembic
CVE-2026-82685
What is CVE-2026-82685?
An authorization bypass vulnerability in Team Alembic's AshAuthentication allows authenticated users to exploit a flaw in the email confirmation mechanism. This security issue enables an attacker to use a confirmation token generated for their account to overwrite the email address associated with another user's account. By doing so, the attacker can gain control over the victim's account, potentially facilitating unauthorized access. The vulnerability arises from the system's insufficient verification of the token against the intended user's record during the confirmation process, resulting in multiple accounts being susceptible. This issue is present in specific versions of the AshAuthentication library and requires immediate attention from users and administrators to implement security patches.
Affected Version(s)
ash_authentication 0.5.0 < 4.15.0
ash_authentication 5.0.0-rc.0 < 5.0.0-rc.14
ash_authentication 1d4bb00617aecae85c33f2ff5bc7e094c6449a6e
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
