{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/ashauthentication/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"id":"CVE-2026-49757"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["AshAuthentication"],"_cs_severities":["medium"],"_cs_tags":["account-takeover","cve-2026-49757","oauth","oidc","authentication-bypass"],"_cs_type":"advisory","_cs_vendors":["Team Alembic"],"content_html":"\u003cp\u003eAshAuthentication, an authentication framework for Elixir/Ash applications, contains a critical vulnerability (CVE-2026-49757) in its OAuth2 and OpenID Connect (OIDC) implementation. The framework incorrectly relies on email addresses to identify users during the account registration and sign-in flow. By design, OIDC requires the use of the \u003ccode\u003eiss\u003c/code\u003e (issuer) and \u003ccode\u003esub\u003c/code\u003e (subject) claim pair to uniquely and securely identify an end-user. AshAuthentication instead performed an upsert action based on the email address, allowing an attacker to register an identity on a third-party OAuth provider using a victim's email address. If the provider allows unverified emails, or if the email address has been reclaimed by the attacker, the application incorrectly maps the attacker's authentication session to the victim's existing local account. This flaw applies to versions 0.1.0 through 4.13.x and 5.0.0-rc.0 through 5.0.0-rc.9, granting attackers full privileges associated with the victim's account.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a target application using the vulnerable AshAuthentication framework.\u003c/li\u003e\n\u003cli\u003eAttacker registers an account on an OAuth or OIDC identity provider, using the email address associated with the victim's account on the target application.\u003c/li\u003e\n\u003cli\u003eAttacker triggers the OAuth/OIDC registration flow on the target application.\u003c/li\u003e\n\u003cli\u003eThe application's \u003ccode\u003eAshAuthentication.Strategy.OAuth2.IdentityChange\u003c/code\u003e module executes an upsert action, locating the victim's existing local record via the email identifier.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003eAshAuthentication.Strategy.OAuth2.SignInPreparation\u003c/code\u003e module fails to validate the \u003ccode\u003eiss\u003c/code\u003e or \u003ccode\u003esub\u003c/code\u003e claims, accepting the attacker's identity as valid for the linked local account.\u003c/li\u003e\n\u003cli\u003eThe application completes the authentication handshake and generates a session token for the victim's account.\u003c/li\u003e\n\u003cli\u003eAttacker gains unauthorized access to the victim's local account, including read, write, and destructive capabilities.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for unauthenticated remote account takeover. Attackers can gain complete control over any victim's account, leading to unauthorized data access, modification, or account deletion within the affected application. Because the default configuration of the strategy is vulnerable, any application using these versions is exposed without needing misconfiguration by the site administrator.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately upgrade AshAuthentication to version 4.14.0 or 5.0.0-rc.10 or later to patch CVE-2026-49757.\u003c/li\u003e\n\u003cli\u003eAudit application logs for anomalous sign-ins involving OAuth providers that have historically allowed unverified email registrations.\u003c/li\u003e\n\u003cli\u003eReview OAuth/OIDC provider configurations to ensure that email verification is strictly enforced and that account reuse policies are disabled where possible.\u003c/li\u003e\n\u003cli\u003eCoordinate with application security teams to perform a post-patch review of authentication logs to identify any sessions initiated by potentially hijacked identities.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-25T18:48:15Z","date_published":"2026-08-25T18:48:15Z","id":"https://feed.craftedsignal.io/briefs/2026-08-ashauthentication-oauth-takeover/","summary":"AshAuthentication incorrectly uses email addresses to link OAuth2/OIDC identities to local accounts, enabling unauthenticated account takeover via identity providers that allow unverified or reclaimed emails.","title":"CVE-2026-49757: AshAuthentication OAuth2/OIDC Account Takeover","url":"https://feed.craftedsignal.io/briefs/2026-08-ashauthentication-oauth-takeover/"}],"language":"en","title":"CraftedSignal Threat Feed - AshAuthentication","version":"https://jsonfeed.org/version/1.1"}