Junglewise Threat Intelligence

CVE-2026-91039: team-alembic ash_authentication authentication bypass by OIDC spoofing

CVE-2026-91039 · Severity: info · Published 2026-09-17

Vendors: Team-Alembic.

Executive brief

ash_authentication is a library that handles user identity and authentication in Ash Framework applications. A flaw in its OpenID Connect (OIDC) strategy allows an attacker controlling one identity provider connection to impersonate users who authenticated through different connections. This breaks the intended isolation between identity providers, enabling unauthorized access to accounts.

Technical details

The vulnerability is an authentication bypass in the dynamic OIDC strategy implementation. The root cause is that connection-specific identity namespacing is intended but never enforced: the __connection_id__ field is set only in ephemeral per-request structs but discarded when re-fetching from the compile-time DSL during identity record writes. Consequently, identity lookups use only the bare strategy name instead of "strategy/connection_id", causing multiple OIDC connections to share the same identity namespace. Since OpenID Connect makes subject (sub) identifiers unique only within an issuer—not across issuers—an attacker can exploit identical or reused subject values across connections to sign in as victims. The identity-match branch executes before email validation, providing no secondary check. No patch availability is indicated in the advisory. Affected versions: 5.0.0-rc.10 through 5.0.0-rc.14.

Affected products

  • team-alembic ash_authentication 5.0.0-rc.10 to 5.0.0-rc.14

Timeline

  • 2026-09-17: disclosed

References