Description
Authentication Bypass by Spoofing vulnerability in team-alembic ash_authentication allows an attacker who can plant a remember-me cookie in a victim's browser to replace that victim's authenticated session with one for the attacker's own account.

AshAuthentication.Plug.Helpers.sign_in_using_remember_me/3 skips re-authenticating an already-signed-in visitor by checking the session for "<subject_name>_token", but store_in_session/2 writes that key only when require_token_presence_for_authentication? is enabled and otherwise writes the bare subject name. At the default setting the guard therefore reads a key that is never written, its already-signed-in branch is unreachable, and the remember-me sign-in runs on every request through the per-request browser pipeline plug. A planted remember-me cookie is consequently honoured even for a visitor holding a live authenticated session, so whatever the victim enters afterwards lands in data the attacker controls. The read path in authenticate_resource_from_session/4 selects the key correctly, so the guard and the reader disagree about which key holds the session.

This issue affects ash_authentication: from 4.10.0 before 4.15.0 and from 5.0.0-rc.0 before 5.0.0-rc.14.
Published: 2026-09-17
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Authentication Bypass
Action: Immediate Patch
AI Analysis

Impact

The vulnerable plug in the Ash Authentication component permits an attacker to replace a victim’s authenticated session with one belonging to the attacker’s own account through a spoofed remember‑me cookie. The plugin checks a session key that is never written unless a specific configuration flag is enabled, so the key is never found, causing the remember‑me pathway to execute on every request. Consequently any operations performed by the victim after the cookie is planted are attributed to the attacker, compromising both confidentiality and integrity of the application data.

Affected Systems

This flaw exists in the Elixir Ash Authentication module for versions from 4.10.0 up to but not including 4.15.0, and from 5.0.0‑rc.0 up to before 5.0.0‑rc.14. Any system using this module with its default configuration (require_token_presence_for_authentication? false) and the remember‑me plug active is affected.

Risk and Exploitability

The CVSS score of 9.1 marks the vulnerability as a high‑severity authentication bypass. Exploitation requires the attacker to plant a remember‑me cookie in the victim’s browser; based on the description, it is inferred that this could be achieved through XSS or similar cookie injection techniques. The EPSS score of less than 1% indicates a low prevalence of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog, suggesting no publicly available zero‑day exploits. Nevertheless, the impact remains critical for applications that do not enforce the token presence flag or that rely on the remember‑me plug for session restoration.

Generated by OpenCVE AI on September 18, 2026 at 23:41 UTC.

Remediation

Vendor Workaround

Set require_token_presence_for_authentication? true on the authenticated resource's token configuration. store_in_session/2 then writes the key the guard reads, so the already-signed-in branch fires and the remember-me sign-in no longer runs against a live session. Note this changes session storage semantics for the whole application and requires a token resource. Otherwise remove the remember-me plug from the browser pipeline, which disables remember-me auto-login entirely.


OpenCVE Recommended Actions

  • Update Ash Authentication to a version that fixes the issue (4.15.0 or later, or 5.0.0‑rc.14 or later).
  • If a patch cannot be applied immediately, configure the token resource to enable require_token_presence_for_authentication? true so that the session key is written; note this changes how session data is stored for the entire application.
  • Alternatively, remove the remember‑me plug from the browser pipeline to disable automatic sign‑in entirely.

Generated by OpenCVE AI on September 18, 2026 at 23:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
Description Authentication Bypass by Spoofing vulnerability in team-alembic ash_authentication allows an attacker who can plant a remember-me cookie in a victim's browser to replace that victim's authenticated session with one for the attacker's own account. AshAuthentication.Plug.Helpers.sign_in_using_remember_me/3 skips re-authenticating an already-signed-in visitor by checking the session for "<subject_name>_token", but store_in_session/2 writes that key only when require_token_presence_for_authentication? is enabled and otherwise writes the bare subject name. At the default setting the guard therefore reads a key that is never written, its already-signed-in branch is unreachable, and the remember-me sign-in runs on every request through the per-request browser pipeline plug. A planted remember-me cookie is consequently honoured even for a visitor holding a live authenticated session, so whatever the victim enters afterwards lands in data the attacker controls. The read path in authenticate_resource_from_session/4 selects the key correctly, so the guard and the reader disagree about which key holds the session. This issue affects ash_authentication: from 4.10.0 before 4.15.0 and from 5.0.0-rc.0 before 5.0.0-rc.14.
Title Remember-me sign-in guard reads a session key that is never written in ash_authentication, allowing session replacement
First Time appeared Team-alembic
Team-alembic ash Authentication
Weaknesses CWE-290
CPEs cpe:2.3:a:team-alembic:ash_authentication:*:*:*:*:*:*:*:*
Vendors & Products Team-alembic
Team-alembic ash Authentication
References
Metrics cvssV4_0

{'score': 9.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Team-alembic Ash Authentication
cve-icon MITRE

Status: PUBLISHED

Assigner: EEF

Published:

Updated: 2026-09-18T14:31:41.806Z

Reserved: 2026-09-17T05:30:01.744Z

Link: CVE-2026-76949

cve-icon Vulnrichment

Updated: 2026-09-18T14:29:29.773Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T22:17:03.883

Modified: 2026-09-18T18:16:18.527

Link: CVE-2026-76949

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T23:45:15Z

Weaknesses
  • CWE-290

    Authentication Bypass by Spoofing