Authentication Bypass Vulnerability in AshAuthentication by Team Alembic
CVE-2026-85500

9.1CRITICAL

Key Information:

Vendor
CVE Published:
17 September 2026

What is CVE-2026-85500?

The vulnerability in the AshAuthentication library allows unconfirmed users to bypass mandatory email confirmation, enabling unauthorized access. The issue arises from the improper validation of user attributes in various configurations, particularly in API layers such as AshGraphql or AshJsonApi. If certain checks are not enforced, the system may treat every user as confirmed, posing a significant security risk. Organizations utilizing versions of AshAuthentication in the specified range should assess their exposure and apply necessary updates.

Affected Version(s)

ash_authentication 4.3.8 < 4.15.0

ash_authentication 5.0.0-rc.0 < 5.0.0-rc.14

ash_authentication 7d37bc6e4df6697b5813d2f373f0fdb08f813f98

References

CVSS V4

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peter Ullrich
Jonatan Männchen / EEF
James Harton
.