Description
Session Fixation vulnerability in team-alembic ash_authentication allows an attacker who can plant a session identifier in a victim's browser to hold an authenticated session once that victim signs in.

AshAuthentication.Plug.Helpers.store_in_session/2 writes the authenticated subject into the existing session with Plug.Conn.put_session/3 and never calls Plug.Conn.configure_session(renew: true), so the identifier the visitor arrived with carries into their authenticated session. Every authentication event reaches this one function: the default success/4 injected by AshAuthentication.Phoenix.Controller.__using__/1, the AuthController emitted by mix ash_authentication_phoenix.install, and remember-me auto-login. AshAuthentication.Phoenix.Plug.store_in_session/2 is a defdelegate to it. Logout does not close the window either, because clear_session/2 ends with Plug.Conn.clear_session/1, which clears session contents but leaves the identifier intact, so a planted identifier survives a logout-then-login cycle.

This issue affects ash_authentication: from 0.2.0 before 4.15.0 and from 5.0.0-rc.0 before 5.0.0-rc.14.
Published: 2026-09-17
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Session fixation enabling unauthorized session hijacking
Action: Upgrade or patch
AI Analysis

Impact

A flaw in the ash_authentication library prevents the session identifier from being regenerated during authentication. An attacker who can plant a valid session ID in a victim’s browser can cause that session ID to survive the login process, allowing the attacker to assume the victim’s identity once the victim authenticates. This can compromise confidentiality, integrity, and availability of user accounts. The weakness is listed as CWE‑384.

Affected Systems

The vulnerability exists in the ash_authentication library from team‑alembic. All releases from 0.2.0 up to but not including 4.15.0, and from 5.0.0‑rc.0 up to but not including 5.0.0‑rc.14, are affected.

Risk and Exploitability

The CVSS score of 7.4 indicates a high risk, while the EPSS score of less than 1% suggests the exploitation probability is currently low. The issue is not yet listed in CISA’s KEV catalog. The likely attack vector involves an attacker influencing the victim’s browser—e.g., through phishing or malicious links—to set a session cookie, making the attack feasible but primarily indirect. Because the flaw allows session hijacking, the impact can be significant for high‑traffic or sensitive applications if the vulnerability is actively exploited.

Generated by OpenCVE AI on September 18, 2026 at 23:31 UTC.

Remediation

Vendor Workaround

Call Plug.Conn.configure_session(conn, renew: true) in your own success/4 before store_in_session/2. This is a one-line change in application code and closes the controller sign-in path, though not remember-me auto-login, which does not pass through application code. Add Plug.Conn.configure_session(conn, drop: true) at sign-out so a planted identifier does not survive a logout-then-login cycle.


OpenCVE Recommended Actions

  • Upgrade ash_authentication to version 4.15.0 or later, or 5.0.0‑rc.14 or later, which contains the upstream fix.
  • If an upgrade is not immediately possible, modify the application’s login success callback to add the line Plug.Conn.configure_session(conn, renew: true) before the call to store_in_session/2 so that the session identifier is regenerated on authentication.
  • Add Plug.Conn.configure_session(conn, drop: true) to the sign‑out workflow to ensure any planted session identifier is cleared after logout, preventing a logout‑then‑login exploitation path.

Generated by OpenCVE AI on September 18, 2026 at 23:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
Description Session Fixation vulnerability in team-alembic ash_authentication allows an attacker who can plant a session identifier in a victim's browser to hold an authenticated session once that victim signs in. AshAuthentication.Plug.Helpers.store_in_session/2 writes the authenticated subject into the existing session with Plug.Conn.put_session/3 and never calls Plug.Conn.configure_session(renew: true), so the identifier the visitor arrived with carries into their authenticated session. Every authentication event reaches this one function: the default success/4 injected by AshAuthentication.Phoenix.Controller.__using__/1, the AuthController emitted by mix ash_authentication_phoenix.install, and remember-me auto-login. AshAuthentication.Phoenix.Plug.store_in_session/2 is a defdelegate to it. Logout does not close the window either, because clear_session/2 ends with Plug.Conn.clear_session/1, which clears session contents but leaves the identifier intact, so a planted identifier survives a logout-then-login cycle. This issue affects ash_authentication: from 0.2.0 before 4.15.0 and from 5.0.0-rc.0 before 5.0.0-rc.14.
Title Session id is not renewed on authentication in ash_authentication, allowing session fixation
First Time appeared Team-alembic
Team-alembic ash Authentication
Weaknesses CWE-384
CPEs cpe:2.3:a:team-alembic:ash_authentication:*:*:*:*:*:*:*:*
Vendors & Products Team-alembic
Team-alembic ash Authentication
References
Metrics cvssV4_0

{'score': 7.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Team-alembic Ash Authentication
cve-icon MITRE

Status: PUBLISHED

Assigner: EEF

Published:

Updated: 2026-09-18T14:31:41.961Z

Reserved: 2026-09-17T00:30:01.485Z

Link: CVE-2026-86688

cve-icon Vulnrichment

Updated: 2026-09-18T14:29:32.046Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T22:17:04.180

Modified: 2026-09-18T18:16:18.527

Link: CVE-2026-86688

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T23:45:15Z

Weaknesses