Session Fixation Vulnerability in AshAuthentication by Team Alembic
CVE-2026-86688

7.4HIGH

Key Information:

Vendor
CVE Published:
17 September 2026

What is CVE-2026-86688?

A session fixation vulnerability exists in AshAuthentication, allowing attackers to exploit session identifiers. Through improper session management, attackers could plant a session identifier in a user's browser. When the user signs in, their session now contains the attacker's identifier, facilitating unauthorized access. This vulnerability stems from a failure to renew session identifiers during authentication, allowing the originally planted identifier to persist across login sessions, including after logout. Affected versions should be updated to mitigate this security risk effectively.

Affected Version(s)

ash_authentication 0.2.0 < 4.15.0

ash_authentication 5.0.0-rc.0 < 5.0.0-rc.14

ash_authentication a939dde9b917c072cdf10c4b0913a9886a4b0231

References

CVSS V4

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peter Ullrich
James Harton
Jonatan Männchen / EEF
.