Junglewise Threat Intelligence

CVE-2026-86522: AshAuthentication log entry forgery via unescaped identity

CVE-2026-86522 · Severity: info · Published 2026-09-17

Vendors: Team-Alembic.

Executive brief

AshAuthentication is an authentication library for Elixir applications. A vulnerability in the password reset functionality allows an attacker to forge application log entries by submitting specially crafted reset requests containing newlines or control characters, potentially masking malicious activity or manipulating audit trails.

Technical details

The vulnerability is an improper output neutralization issue (CWE-117: Improper Output Neutralization for Logs) in the RequestPasswordReset.run/3 function. The identity parameter (email or username) from password reset requests is interpolated directly into Logger.warning/1 heredocs without escaping, allowing newline and control characters to terminate log records and inject forged log lines. An unauthenticated attacker can exploit this via a crafted password reset request. The vulnerability affects ash_authentication versions 4.2.0–4.14.x and 5.0.0-rc.0–5.0.0-rc.13; patches are available in 4.15.0 and 5.0.0-rc.14.

Affected products

  • team-alembic AshAuthentication 4.2.0 before 4.15.0, 5.0.0-rc.0 before 5.0.0-rc.14

Timeline

  • 2026-09-17: disclosed

References