Junglewise Threat Intelligence

CVE-2026-81637: team-alembic AshAuthentication OAuth2 state replay in callback

CVE-2026-81637 · Severity: info · Published 2026-09-17

Vendors: Team-Alembic.

Executive brief

AshAuthentication is a library used by Elixir web applications to handle user authentication via OAuth2 providers. A session validation bug allows attackers who intercept an OAuth2 state parameter to bypass authentication controls and force a victim to log into an attacker-controlled account, leading to account takeover.

Technical details

The vulnerability is an insufficient session expiration issue in AshAuthentication.Strategy.OAuth2.Plug.callback/2. The module fails to clear the OAuth2 state value (stored in session_params) when authentication fails, completes, or is cancelled—only clearing it on successful login. Due to incorrect control flow in an Elixir with/else chain, the session entry persists until the next request phase or natural session expiry. An attacker obtaining a victim's OAuth2 state value can replay the OAuth2 callback to authenticate that victim into an attacker-controlled account. The vulnerability affects ash_authentication versions 0.6.0 through 4.15.0 (exclusive) and 5.0.0-rc.0 through 5.0.0-rc.14 (exclusive); patches are available in 4.15.0 and 5.0.0-rc.14 or later.

Affected products

  • team-alembic AshAuthentication 0.6.0 to 4.14.x; 5.0.0-rc.0 to 5.0.0-rc.13

Timeline

  • 2026-09-17: disclosed

References