Sensitive Information Leakage in AshAuthentication by Team Alembic
CVE-2026-82723
What is CVE-2026-82723?
The AshAuthentication plugin by Team Alembic features a vulnerability where sensitive user password digests can be exposed in audit log entries. The plugin mistakenly includes the hashed_password attribute in audit logs when operations are performed by users, allowing these digests to accumulate in the audit store. Without proper controls, users with access to the audit logs can potentially exploit this condition to retrieve password digests and perform offline attacks on user accounts. This issue arises during routine authenticated activities, marking a significant concern for any developers utilizing affected versions of the AshAuthentication plugin.
Affected Version(s)
ash_authentication 4.12.0 < 4.15.0
ash_authentication 5.0.0-rc.0 < 5.0.0-rc.2
ash_authentication 255cfc9c0e511b7e0de39f8b3d676ae994fae06c
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
