Junglewise Threat Intelligence

CVE-2026-86533: team-alembic AshAuthentication session fixation in revoked sessions

CVE-2026-86533 · Severity: info · Published 2026-09-17

Vendors: Team-Alembic.

Executive brief

AshAuthentication, a user authentication library for the Elixir web framework, fails to properly revoke sessions after a user signs out. An attacker who captures a valid session cookie before the user logs out can continue using that session indefinitely, even after the legitimate user revokes it. This allows unauthorized access to user accounts and protected resources.

Technical details

The vulnerability is a session fixation / insufficient session expiration bug in two components: AshAuthentication.Plug.Helpers.authenticate_resource_from_session/4 and AshAuthentication.Phoenix.LiveSession.on_mount/4. When a resource is configured with session_identifier :jti, the session stores a value as <jti>:<subject>. On session validation, both functions split this value, discard the jti (which identifies the specific revocation record), and reload the user from the database using only the subject. The jti is never consulted, so revoked sessions remain valid. The token-presence authentication path does check revocation status via AshAuthentication.TokenResource.Actions.get_token/3, but the session-only path does not. Affected versions: ash_authentication 4.9.1–4.14.x and 5.0.0-rc.0–5.0.0-rc.13; ash_authentication_phoenix 2.10.0–2.17.3 and 3.0.0-rc.0–3.0.0-rc.10. Patches are available in ash_authentication 4.15.0+, 5.0.0-rc.14+ and ash_authentication_phoenix 2.17.4+, 3.0.0-rc.11+.

Affected products

  • team-alembic AshAuthentication 4.9.1 to 4.14.x; 5.0.0-rc.0 to 5.0.0-rc.13
  • team-alembic AshAuthentication Phoenix 2.10.0 to 2.17.3; 3.0.0-rc.0 to 3.0.0-rc.10

Timeline

  • 2026-09-17: published

References