Description
Insufficient Session Expiration vulnerability in team-alembic AshAuthentication and AshAuthentication Phoenix allows a revoked session to remain fully authenticated.

A resource configured with session_identifier :jti and require_token_presence_for_authentication? disabled stores its session value as <jti>:<subject>. The jti is there so that signing out can revoke that one session. Neither reader consults it: AshAuthentication.Plug.Helpers.authenticate_resource_from_session/4 and AshAuthentication.Phoenix.LiveSession.on_mount/4 both split the value with split_identifier/2, discard the jti and pass the bare subject to AshAuthentication.subject_to_user/3, which reloads the record. The token-presence branch of each function does check its token, calling AshAuthentication.TokenResource.Actions.get_token/3 with the jti and the purpose user. Because the revocation record is never read, neither its revoked state nor its expiry constrains the session, so a session captured before sign-out keeps working.

This issue affects ash_authentication: from 4.9.1 before 4.15.0 and from 5.0.0-rc.0 before 5.0.0-rc.14; ash_authentication_phoenix: from 2.10.0 before 2.17.4 and from 3.0.0-rc.0 before 3.0.0-rc.11.
Published: 2026-09-17
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Session Persistence
Action: Immediate Patch
AI Analysis

Impact

A flaw in AshAuthentication and AshAuthentication Phoenix causes the jti portion of a session identifier to be ignored during authentication. Because the revocation record is never consulted, a session that has been signed out remains fully authenticated. This allows an attacker who obtains a valid session token before revocation to maintain access to protected resources after the legitimate user has logged out, effectively bypassing the intended session invalidation. The vulnerability represents a severe authentication bypass, enabling unauthorized persistence of access for the lifetime of the session.

Affected Systems

The issue affects team‑alembic AshAuthentication from versions 4.9.1 up to but not including 4.15.0 and from 5.0.0‑rc.0 up to but not including 5.0.0‑rc.14. Contained within team‑alembic AshAuthentication Phoenix, the vulnerability exists in versions 2.10.0 through 2.17.3 and in 3.0.0‑rc.0 through 3.0.0‑rc.10. All other versions are unaffected.

Risk and Exploitability

With a CVSS score of 9.1, the vulnerability is classified as critical. The EPSS score is not available, and it is not listed in the CISA KEV catalog, but the high severity score indicates a high likelihood of exploitation if a valid session token is captured. The attack vector is remote, relying on an attacker’s possession of an active session id. Once a session has been captured, the revocation mechanism does not prevent further use, allowing the attacker to maintain uninterrupted access to the affected application.

Generated by OpenCVE AI on September 17, 2026 at 22:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade team‑alembic AshAuthentication to version 4.15.0 or later, or to 5.0.0‑rc.14 or later, and upgrade AshAuthentication Phoenix to version 2.17.4 or later, or to 3.0.0‑rc.11 or later.
  • After applying the patch, revoke all active sessions and require users to log in again to generate fresh tokens.
  • Continuously monitor authentication logs for reuse of stale session identifiers and enforce additional verification checks if necessary.

Generated by OpenCVE AI on September 17, 2026 at 22:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
Description Insufficient Session Expiration vulnerability in team-alembic AshAuthentication and AshAuthentication Phoenix allows a revoked session to remain fully authenticated. A resource configured with session_identifier :jti and require_token_presence_for_authentication? disabled stores its session value as <jti>:<subject>. The jti is there so that signing out can revoke that one session. Neither reader consults it: AshAuthentication.Plug.Helpers.authenticate_resource_from_session/4 and AshAuthentication.Phoenix.LiveSession.on_mount/4 both split the value with split_identifier/2, discard the jti and pass the bare subject to AshAuthentication.subject_to_user/3, which reloads the record. The token-presence branch of each function does check its token, calling AshAuthentication.TokenResource.Actions.get_token/3 with the jti and the purpose user. Because the revocation record is never read, neither its revoked state nor its expiry constrains the session, so a session captured before sign-out keeps working. This issue affects ash_authentication_phoenix: from 2.10.0 before 2.17.4 and from 3.0.0-rc.0 onward; ash_authentication: from 4.9.1 before 4.15.0 and from 5.0.0-rc.0 before 5.0.0-rc.14. Insufficient Session Expiration vulnerability in team-alembic AshAuthentication and AshAuthentication Phoenix allows a revoked session to remain fully authenticated. A resource configured with session_identifier :jti and require_token_presence_for_authentication? disabled stores its session value as <jti>:<subject>. The jti is there so that signing out can revoke that one session. Neither reader consults it: AshAuthentication.Plug.Helpers.authenticate_resource_from_session/4 and AshAuthentication.Phoenix.LiveSession.on_mount/4 both split the value with split_identifier/2, discard the jti and pass the bare subject to AshAuthentication.subject_to_user/3, which reloads the record. The token-presence branch of each function does check its token, calling AshAuthentication.TokenResource.Actions.get_token/3 with the jti and the purpose user. Because the revocation record is never read, neither its revoked state nor its expiry constrains the session, so a session captured before sign-out keeps working. This issue affects ash_authentication: from 4.9.1 before 4.15.0 and from 5.0.0-rc.0 before 5.0.0-rc.14; ash_authentication_phoenix: from 2.10.0 before 2.17.4 and from 3.0.0-rc.0 before 3.0.0-rc.11.

Thu, 17 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description Insufficient Session Expiration vulnerability in team-alembic AshAuthentication and AshAuthentication Phoenix allows a revoked session to remain fully authenticated. A resource configured with session_identifier :jti and require_token_presence_for_authentication? disabled stores its session value as <jti>:<subject>. The jti is there so that signing out can revoke that one session. Neither reader consults it: AshAuthentication.Plug.Helpers.authenticate_resource_from_session/4 and AshAuthentication.Phoenix.LiveSession.on_mount/4 both split the value with split_identifier/2, discard the jti and pass the bare subject to AshAuthentication.subject_to_user/3, which reloads the record. The token-presence branch of each function does check its token, calling AshAuthentication.TokenResource.Actions.get_token/3 with the jti and the purpose user. Because the revocation record is never read, neither its revoked state nor its expiry constrains the session, so a session captured before sign-out keeps working. This issue affects ash_authentication_phoenix: from 2.10.0 before 2.17.4 and from 3.0.0-rc.0 onward; ash_authentication: from 4.9.1 before 4.15.0 and from 5.0.0-rc.0 before 5.0.0-rc.14.
Title Revoked session accepted because the session jti is never checked in AshAuthentication and AshAuthentication Phoenix
First Time appeared Team-alembic
Team-alembic ash Authentication
Team-alembic ash Authentication Phoenix
Weaknesses CWE-613
CPEs cpe:2.3:a:team-alembic:ash_authentication:*:*:*:*:*:*:*:*
cpe:2.3:a:team-alembic:ash_authentication_phoenix:*:*:*:*:*:*:*:*
Vendors & Products Team-alembic
Team-alembic ash Authentication
Team-alembic ash Authentication Phoenix
References
Metrics cvssV4_0

{'score': 9.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Team-alembic Ash Authentication Ash Authentication Phoenix
cve-icon MITRE

Status: PUBLISHED

Assigner: EEF

Published:

Updated: 2026-09-17T18:17:21.199Z

Reserved: 2026-09-11T18:00:02.036Z

Link: CVE-2026-86533

cve-icon Vulnrichment

Updated: 2026-09-17T18:17:15.369Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T14:17:46.467

Modified: 2026-09-18T18:16:18.527

Link: CVE-2026-86533

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T23:00:13Z

Weaknesses
  • CWE-613

    Insufficient Session Expiration