One-Way Hash Vulnerability in AshAuthentication by Team Alembic
CVE-2026-82759

1.8LOW

Key Information:

Vendor
CVE Published:
17 September 2026

What is CVE-2026-82759?

A vulnerability in AshAuthentication allows the exposure of client IP addresses by exploiting a predictable salt during hash computation. The method computes a hash using SHA-256 with either a specified or default salt, leading to potential identification of source IPs through precomputation. In cases where the default salt is utilized, IP addresses can easily be mapped back, undermining the privacy protections intended by the hash mechanism. This flaw affects specific versions of the AshAuthentication plugin, requiring immediate attention to secure user data.

Affected Version(s)

ash_authentication 4.12.0 < 4.15.0

ash_authentication 5.0.0-rc.0 < 5.0.0-rc.14

ash_authentication 255cfc9c0e511b7e0de39f8b3d676ae994fae06c

References

CVSS V4

Score:
1.8
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jonatan Männchen / EEF
James Harton
Peter Ullrich
.