Authentication Bypass Vulnerability in AshAuthentication by Team Alembic
CVE-2026-85500
9.1CRITICAL
What is CVE-2026-85500?
The vulnerability in the AshAuthentication library allows unconfirmed users to bypass mandatory email confirmation, enabling unauthorized access. The issue arises from the improper validation of user attributes in various configurations, particularly in API layers such as AshGraphql or AshJsonApi. If certain checks are not enforced, the system may treat every user as confirmed, posing a significant security risk. Organizations utilizing versions of AshAuthentication in the specified range should assess their exposure and apply necessary updates.
Affected Version(s)
ash_authentication 4.3.8 < 4.15.0
ash_authentication 5.0.0-rc.0 < 5.0.0-rc.14
ash_authentication 7d37bc6e4df6697b5813d2f373f0fdb08f813f98
References
CVSS V4
Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Peter Ullrich
Jonatan Männchen / EEF
James Harton
