Junglewise Threat Intelligence

CVE-2026-85500: team-alembic AshAuthentication authentication bypass in password verification

CVE-2026-85500 · Severity: info · CVSS 6.5 · Published 2026-09-17

Vendors: Team-Alembic.

Executive brief

AshAuthentication is an Elixir authentication library used to manage user login and registration flows. A logic flaw allows unconfirmed users to bypass mandatory email confirmation requirements and obtain active sessions, potentially granting unauthorized access to user accounts and application features.

Technical details

The vulnerability exists in the check_user/2 function of AshAuthentication.Strategy.Password.Actions, which uses a bare is_nil() check to verify whether a required confirmation attribute is set. The check fails when the attribute is not selected on the loaded record (returning %Ash.NotLoaded{}) or when a field policy denies access (returning %Ash.ForbiddenField{}), neither of which equals nil. Additionally, the require_confirmed_with check is only enforced inside the Password.Actions module and not on the action itself, allowing direct action invocation (as used by GraphQL and JSON API layers) to skip the check entirely. An attacker can register or sign in directly via these API layers without completing email confirmation, gaining an authenticated session.

Affected products

  • team-alembic AshAuthentication 4.3.8 to before 4.15.0, 5.0.0-rc.0 to before 5.0.0-rc.14

Timeline

  • 2026-09-17: disclosed
  • 2026-09-17: advisory

References