Executive brief
Ash Authentication is an authentication library used in Elixir/Phoenix web applications. An authenticated attacker can hijack another user's account by replaying their own email confirmation token against a victim's record, allowing them to change the victim's email address and take over the account through a password reset.
Technical details
The vulnerability is an authorization bypass in AshAuthentication.AddOn.Confirmation.ConfirmChange, which verifies a confirmation token's signature and act claim but fails to validate that the sub (subject) claim matches the target user record. An authenticated attacker can generate a confirmation token for their own email change, then replay that token against a victim's record ID using force_change_attributes/2 to write their email address and stamp confirmed_at. This enables account takeover via password reset. The library's own confirmation flow (Actions.confirm/3) is unaffected because it resolves the sub claim to a user before targeting the record. Attack requires prior authentication.
Affected products
- team-alembic Ash Authentication 0.5.0 before 4.15.0 and 5.0.0-rc.0 before 5.0.0-rc.14
Timeline
- 2026-09-17: disclosed