Junglewise Threat Intelligence

CVE-2026-82685: Ash Authentication authorization bypass in email confirmation

CVE-2026-82685 · Severity: info · Published 2026-09-17

Vendors: Team-Alembic.

Executive brief

Ash Authentication is an authentication library used in Elixir/Phoenix web applications. An authenticated attacker can hijack another user's account by replaying their own email confirmation token against a victim's record, allowing them to change the victim's email address and take over the account through a password reset.

Technical details

The vulnerability is an authorization bypass in AshAuthentication.AddOn.Confirmation.ConfirmChange, which verifies a confirmation token's signature and act claim but fails to validate that the sub (subject) claim matches the target user record. An authenticated attacker can generate a confirmation token for their own email change, then replay that token against a victim's record ID using force_change_attributes/2 to write their email address and stamp confirmed_at. This enables account takeover via password reset. The library's own confirmation flow (Actions.confirm/3) is unaffected because it resolves the sub claim to a user before targeting the record. Attack requires prior authentication.

Affected products

  • team-alembic Ash Authentication 0.5.0 before 4.15.0 and 5.0.0-rc.0 before 5.0.0-rc.14

Timeline

  • 2026-09-17: disclosed

References