Insufficient Session Expiration in AshAuthentication and AshAuthentication Phoenix by Team Alembic
CVE-2026-86533

9.1CRITICAL

What is CVE-2026-86533?

The vulnerability involves an insufficient session expiration in AshAuthentication and AshAuthentication Phoenix, where revoked sessions remain fully authenticated after sign-out. This occurs because the current implementation does not adequately check the revocation status of sessions, allowing unauthorized access to resources. The session identifier is improperly handled, leading to potential security breaches as the system fails to invalidate sessions correctly. Users of affected versions should apply the necessary updates to mitigate risks associated with this vulnerability.

Affected Version(s)

ash_authentication 4.9.1 < 4.15.0

ash_authentication 5.0.0-rc.0 < 5.0.0-rc.14

ash_authentication fcaeb73f76f8f2e9aef8bf637690d2a20dd97596

References

CVSS V4

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peter Ullrich
Jonatan Männchen / EEF
James Harton
.