Junglewise Threat Intelligence

CVE-2026-80218: team-alembic AshAuthentication token confusion between resources

CVE-2026-80218 · Severity: info · CVSS 7.5 · Published 2026-09-17

Vendors: Team-Alembic.

Executive brief

AshAuthentication is an authentication library used in Elixir web applications to manage user sign-in across different resources. A vulnerability allows an attacker with a valid sign-in token for one resource to gain unauthorized access as a user on a completely different resource. This could enable account takeover and unauthorized access to sensitive data without requiring additional credentials.

Technical details

The vulnerability is an improper authentication issue in the JWT token parsing logic of AshAuthentication.Strategy.Password.SignInWithTokenPreparation. The extract_primary_keys_from_subject/2 function uses URI.parse/1 to extract the JWT subject claim but discards the path segment that identifies which resource the token was issued for, retaining only the query string. Subsequent validation (AshAuthentication.Jwt.verify/3) checks signature, expiration, and library version, but does not verify the resource binding. Since primary-key field names are identical across resources, an attacker can reuse a token from one resource to authenticate as a user on another. The vulnerability affects multiple sign-in preparations (Password, WebAuthn, remember-me) but not magic link sign-in. Patched versions are available starting at 4.15.0 and 5.0.0-rc.14.

Affected products

  • team-alembic AshAuthentication 3.10.5 before 4.15.0, 5.0.0-rc.0 before 5.0.0-rc.14

Timeline

  • 2026-09-17: disclosed: CVE-2026-80218 published on NVD

References