EEF-CVE-2026-82685
Confirmation token accepted on any record in AshAuthentication
Quick fix
EEF-CVE-2026-82685 — ash_authentication: upgrade to the fixed version with the command below.
mix deps.update ash_authenticationDetails
## Summary
Authorization Bypass Through User-Controlled Key vulnerability in team-alembic AshAuthentication allows an authenticated attacker to overwrite and confirm another user's email address, and so take over that account. A confirmation token issued to one user is accepted on any other user's record.
`AshAuthentication.AddOn.Confirmation.ConfirmChange` verifies the token's signature and its `act` claim, then applies the changes stored against that token to whichever record the changeset targets, never comparing the `sub` claim against `changeset.data`. An attacker who registers an account and changes their own email replays the resulting token against a victim's record id, writing in their own address with `force_change_attributes/2` and stamping `confirmed_at`, after which an ordinary password reset yields the account. The library's own confirmation flow is unaffected, because `AshAuthentication.AddOn.Confirmation.Actions.confirm/3` resolves `sub` to a user and targets that record.
This issue affects ash_authentication: from 0.5.0 before 4.15.0 and from 5.0.0-rc.0 before 5.0.0-rc.14.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/team-alembic/ash_authentication/security/advisories/GHSA-g636-26vf-2w63[ADVISORY]
- https://cna.erlef.org/cves/CVE-2026-82685.html[WEB]
- https://github.com/team-alembic/ash_authentication/commit/1d4bb00617aecae85c33f2ff5bc7e094c6449a6e[WEB]
- https://github.com/team-alembic/ash_authentication/commit/d7c15c21d39c009206e010cd67e2d86370fe7a28[FIX]
- https://github.com/team-alembic/ash_authentication/commit/2a2396af131ab67e2f445b805fecce8e6ca86c0e[FIX]
- https://hex.pm/packages/ash_authentication[PACKAGE]