Improper Output Neutralization Vulnerability in AshAuthentication by Team-Alembic
CVE-2026-86522

6.3MEDIUM

Key Information:

Vendor
CVE Published:
17 September 2026

What is CVE-2026-86522?

The AshAuthentication component from Team-Alembic is affected by a vulnerability that allows unauthenticated attackers to manipulate application log entries. By submitting a password reset identity with newlines or control characters, attackers can craft log messages that misrepresent the application's actions. This occurs because the identity input, taken directly from user requests, is logged without proper sanitization, leading to the potential for serious misrepresentation of system events. Users are advised to update to secure versions to prevent exploitation.

Affected Version(s)

ash_authentication 4.2.0 < 4.15.0

ash_authentication 5.0.0-rc.0 < 5.0.0-rc.14

ash_authentication 3954f277929712755aef57a4a3a821688f121316

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peter Ullrich
Jonatan Männchen / EEF
James Harton
.