Description
Improper Authentication vulnerability in team-alembic AshAuthentication allows an attacker to be signed in as another user by linking an OAuth2 identity to an account that is not theirs.

AshAuthentication.Strategy.OAuth2.UserResolver.resolve/3 matches an existing account using the register action's upsert_identity keys, then gates linking the incoming provider identity to it on email_trusted?/2, which reads only the provider's email_verified boolean and never compares the provider's email value with the matched account's email. That gate assumes the account was matched by its email field, so under any other upsert_identity it is vacuous and an attacker presenting their own verified email is attached to, and issued a session for, an account matched on some other attribute. The same unguarded gate applies in OAuth2.SignInPreparation on the registration_enabled? false path, where the account is matched by the sign-in action's read filter instead. The upsert also rewrites the matched account's email to the attacker's address, so later account recovery reaches the attacker rather than the owner.

This issue affects ash_authentication: from 4.14.0 before 4.15.0 and from 5.0.0-rc.10 before 5.0.0-rc.14.
Published: 2026-09-17
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Impersonation via OAuth2 Identity Linking
Action: Immediate Patch
AI Analysis

Impact

The vulnerability in team‑alembic’s AshAuthentication allows an attacker to sign in as an unrelated user by linking a verified OAuth2 identity to that user’s account. The code matches an existing account using credentials other than the email field, and then blindly trusts the provider’s verified flag without comparing the provider email to the stored account email. As a result, an attacker can attach their own OAuth2 account to any existing account and receive a valid session, effectively hijacking that account. The flaw also rewrites the matched account’s email address to the attacker’s, compromising future account recovery and security controls.

Affected Systems

Team‑alembic’s AshAuthentication components are affected in version ranges 4.14.0 to before 4.15.0 and 5.0.0‑rc.10 to before 5.0.0‑rc.14. All installations of AshAuthentication matching those ranges should be treated as vulnerable.

Risk and Exploitability

The CVSS score of 9.1 categorizes the flaw as critical, indicating significant impact and difficulty of exploitation. EPSS information is not available, but the flaw is listed as not included in the CISA KEV catalog. Attackers need only a valid OAuth2 provider account with a verified email; the flaw does not require any special privileges or local access. The attack can be performed remotely via the normal OAuth2 sign‑in or registration path, making it easily exploitable by a wide range of adversaries.

Generated by OpenCVE AI on September 17, 2026 at 21:18 UTC.

Remediation

Vendor Solution

Upgrading prevents new links but does not unpick existing ones. An account already linked through this path stays linked, and a victim's email may already have been rewritten to the attacker's address. Operators whose register action or sign-in action matched on anything other than the email should review their UserIdentity rows for links whose provider email does not match the linked account's email, and check affected accounts for a rewritten email address.


Vendor Workaround

Set trust_email_verified? false on the affected strategy, which refuses the sign-in rather than linking it and closes both the register and the sign-in path. Alternatively, key the register action's upsert_identity, or the sign-in action's read filter, on the email attribute, which restores the premise the gate assumes.


OpenCVE Recommended Actions

  • Upgrade AshAuthentication to a version above 4.15.0 or 5.0.0‑rc.14 to prevent new links from being created. This does not remove previously established links, so it should be followed by an audit.
  • Carefully review the UserIdentity rows for any linked identities where the provider’s email does not match the linked account’s email, and examine affected accounts for email addresses that have been altered to an attacker’s address.
  • If a quick temporary fix is needed, set the trust_email_verified? option to false on the affected strategy or modify the register action’s upsert_identity keys or the sign‑in action’s read filter to include an email comparison.

Generated by OpenCVE AI on September 17, 2026 at 21:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Description Improper Authentication vulnerability in team-alembic AshAuthentication allows an attacker to be signed in as another user by linking an OAuth2 identity to an account that is not theirs. AshAuthentication.Strategy.OAuth2.UserResolver.resolve/3 matches an existing account using the register action's upsert_identity keys, then gates linking the incoming provider identity to it on email_trusted?/2, which reads only the provider's email_verified boolean and never compares the provider's email value with the matched account's email. That gate assumes the account was matched by its email field, so under any other upsert_identity it is vacuous and an attacker presenting their own verified email is attached to, and issued a session for, an account matched on some other attribute. The same unguarded gate applies in OAuth2.SignInPreparation on the registration_enabled? false path, where the account is matched by the sign-in action's read filter instead. The upsert also rewrites the matched account's email to the attacker's address, so later account recovery reaches the attacker rather than the owner. This issue affects ash_authentication: from 4.14.0 before 4.15.0 and from 5.0.0-rc.10 before 5.0.0-rc.14.
Title OAuth2 sign-in attached to an existing account without an email comparison in AshAuthentication
First Time appeared Team-alembic
Team-alembic ash Authentication
Weaknesses CWE-287
CPEs cpe:2.3:a:team-alembic:ash_authentication:*:*:*:*:*:*:*:*
Vendors & Products Team-alembic
Team-alembic ash Authentication
References
Metrics cvssV4_0

{'score': 9.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Team-alembic Ash Authentication
cve-icon MITRE

Status: PUBLISHED

Assigner: EEF

Published:

Updated: 2026-09-17T19:32:55.621Z

Reserved: 2026-09-16T10:30:02.169Z

Link: CVE-2026-88952

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-17T15:16:56.290

Modified: 2026-09-18T18:16:18.527

Link: CVE-2026-88952

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:30:18Z

Weaknesses