EEF-CVE-2026-86533
Revoked session accepted because the session jti is never checked in AshAuthentication and AshAuthentication Phoenix
Quick fix
EEF-CVE-2026-86533 — ash_authentication: upgrade to the fixed version with the command below.
mix deps.update ash_authenticationDetails
## Summary
Insufficient Session Expiration vulnerability in team-alembic AshAuthentication and AshAuthentication Phoenix allows a revoked session to remain fully authenticated.
A resource configured with `session_identifier :jti` and `require_token_presence_for_authentication?` disabled stores its session value as `<jti>:<subject>`. The `jti` is there so that signing out can revoke that one session. Neither reader consults it: `AshAuthentication.Plug.Helpers.authenticate_resource_from_session/4` and `AshAuthentication.Phoenix.LiveSession.on_mount/4` both split the value with `split_identifier/2`, discard the `jti` and pass the bare subject to `AshAuthentication.subject_to_user/3`, which reloads the record. The token-presence branch of each function does check its token, calling `AshAuthentication.TokenResource.Actions.get_token/3` with the `jti` and the purpose `user`. Because the revocation record is never read, neither its revoked state nor its expiry constrains the session, so a session captured before sign-out keeps working.
This issue affects ash_authentication: from 4.9.1 before 4.15.0 and from 5.0.0-rc.0 before 5.0.0-rc.14; ash_authentication_phoenix: from 2.10.0 before 2.17.4 and from 3.0.0-rc.0 before 3.0.0-rc.11.
Are you affected?
Enter the version of the package you're using.
Affected packages
2.10.0Fixed in: 2.17.4mix deps.update ash_authentication_phoenixReferences
- https://github.com/team-alembic/ash_authentication_phoenix/security/advisories/GHSA-m6x4-4gvp-xwjr[ADVISORY]
- https://cna.erlef.org/cves/CVE-2026-86533.html[WEB]
- https://github.com/team-alembic/ash_authentication/security/advisories/GHSA-w374-hvrx-66hg[ADVISORY]
- https://github.com/team-alembic/ash_authentication/commit/fcaeb73f76f8f2e9aef8bf637690d2a20dd97596[WEB]
- https://github.com/team-alembic/ash_authentication/commit/a3f49f758f013d2ff086dd9c5ef2d94e921711b4[FIX]
- https://github.com/team-alembic/ash_authentication/commit/e28e911caa9728d76329afdb0fb26742ffe4eeef[FIX]
- https://github.com/team-alembic/ash_authentication_phoenix/commit/a3253fb4fc7145aeb403537af1c24d3a8d51ffb1[WEB]
- https://github.com/team-alembic/ash_authentication_phoenix/commit/0135217e34e621dac79ae3d9559aeee49304b0aa[WEB]
- https://github.com/team-alembic/ash_authentication_phoenix/commit/f7ab005a2aac09707a25521653c94893d328cc52[FIX]
- https://hex.pm/packages/ash_authentication[PACKAGE]
- https://hex.pm/packages/ash_authentication_phoenix[PACKAGE]