Improper Output Neutralization Vulnerability in AshAuthentication by Team-Alembic
CVE-2026-86522
What is CVE-2026-86522?
The AshAuthentication component from Team-Alembic is affected by a vulnerability that allows unauthenticated attackers to manipulate application log entries. By submitting a password reset identity with newlines or control characters, attackers can craft log messages that misrepresent the application's actions. This occurs because the identity input, taken directly from user requests, is logged without proper sanitization, leading to the potential for serious misrepresentation of system events. Users are advised to update to secure versions to prevent exploitation.
Affected Version(s)
ash_authentication 4.2.0 < 4.15.0
ash_authentication 5.0.0-rc.0 < 5.0.0-rc.14
ash_authentication 3954f277929712755aef57a4a3a821688f121316
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
