Junglewise Threat Intelligence

CVE-2026-55954: Ueberauth ueberauth_apple authentication bypass in ID token validation

CVE-2026-55954 · Severity: info · CVSS 9.1 · Published 2026-07-14

Executive brief

A security flaw in the Apple authentication library for Elixir applications allows attackers to bypass login procedures and take over user accounts. The software fails to properly check the validity of security tokens provided by Apple, meaning an attacker could reuse old or stolen tokens to impersonate legitimate users. This could lead to unauthorized access to sensitive customer data and account hijacking across different applications managed by the same developer team.

Technical details

The vulnerability exists in the Ueberauth.Strategy.Apple.Token.payload/2 function, which verifies the JWT signature against Apple's JWKS but fails to validate registered claims including 'iss', 'aud', 'exp', and 'iat'. Because the 'sub' claim is used directly to derive the user's identity without checking if the token has expired or was intended for the specific application, an attacker can perform a session replay attack. By obtaining a valid Apple-signed ID token (even an expired one or one issued for a different client within the same Apple developer team), an attacker can bypass authentication and gain access as the victim. The issue is fixed in version 0.6.2.

Affected products

  • ueberauth ueberauth_apple 0.1.0 to 0.6.1

Timeline

  • 2026-07-13: patched: Version 0.6.2 released
  • 2026-07-14: advisory: CVE-2026-55954 published

References