Sensitive Information Leakage in AshAuthentication by Team Alembic
CVE-2026-82723

1.8LOW

Key Information:

Vendor
CVE Published:
17 September 2026

What is CVE-2026-82723?

The AshAuthentication plugin by Team Alembic features a vulnerability where sensitive user password digests can be exposed in audit log entries. The plugin mistakenly includes the hashed_password attribute in audit logs when operations are performed by users, allowing these digests to accumulate in the audit store. Without proper controls, users with access to the audit logs can potentially exploit this condition to retrieve password digests and perform offline attacks on user accounts. This issue arises during routine authenticated activities, marking a significant concern for any developers utilizing affected versions of the AshAuthentication plugin.

Affected Version(s)

ash_authentication 4.12.0 < 4.15.0

ash_authentication 5.0.0-rc.0 < 5.0.0-rc.2

ash_authentication 255cfc9c0e511b7e0de39f8b3d676ae994fae06c

References

CVSS V4

Score:
1.8
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

James Harton
Peter Ullrich
Jonatan Männchen
.