Insufficient Session Expiration in AshAuthentication and AshAuthentication Phoenix by Team Alembic
CVE-2026-86533
Key Information:
- Vendor
Team-alembic
- Vendor
- CVE Published:
- 17 September 2026
What is CVE-2026-86533?
The vulnerability involves an insufficient session expiration in AshAuthentication and AshAuthentication Phoenix, where revoked sessions remain fully authenticated after sign-out. This occurs because the current implementation does not adequately check the revocation status of sessions, allowing unauthorized access to resources. The session identifier is improperly handled, leading to potential security breaches as the system fails to invalidate sessions correctly. Users of affected versions should apply the necessary updates to mitigate risks associated with this vulnerability.
Affected Version(s)
ash_authentication 4.9.1 < 4.15.0
ash_authentication 5.0.0-rc.0 < 5.0.0-rc.14
ash_authentication fcaeb73f76f8f2e9aef8bf637690d2a20dd97596
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
