{"id":"CVE-2026-82685","aliases":["GHSA-g636-26vf-2w63"],"url":"https://o3.security/vulnerability/CVE-2026-82685","summary":"Confirmation token accepted on any record in AshAuthentication","details":"## Summary\n\nAuthorization Bypass Through User-Controlled Key vulnerability in team-alembic AshAuthentication allows an authenticated attacker to overwrite and confirm another user's email address, and so take over that account. A confirmation token issued to one user is accepted on any other user's record.\n\n`AshAuthentication.AddOn.Confirmation.ConfirmChange` verifies the token's signature and its `act` claim, then applies the changes stored against that token to whichever record the changeset targets, never comparing the `sub` claim against `changeset.data`. An attacker who registers an account and changes their own email replays the resulting token against a victim's record id, writing in their own address with `force_change_attributes/2` and stamping `confirmed_at`, after which an ordinary password reset yields the account. The library's own confirmation flow is unaffected, because `AshAuthentication.AddOn.Confirmation.Actions.confirm/3` resolves `sub` to a user and targets that record.\n\nThis issue affects ash_authentication: from 0.5.0 before 4.15.0 and from 5.0.0-rc.0 before 5.0.0-rc.14.","published":"2026-09-17T13:08:56.491Z","modified":"2026-09-17T13:26:04.340611555Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Hex","name":"ash_authentication","fixedVersion":"4.15.0"}],"fix":{"url":"https://github.com/team-alembic/ash_authentication/commit/d7c15c21d39c009206e010cd67e2d86370fe7a28","label":"team-alembic/ash_authentication@d7c15c2"},"references":[{"type":"ADVISORY","url":"https://github.com/team-alembic/ash_authentication/security/advisories/GHSA-g636-26vf-2w63"},{"type":"WEB","url":"https://cna.erlef.org/cves/CVE-2026-82685.html"},{"type":"WEB","url":"https://github.com/team-alembic/ash_authentication/commit/1d4bb00617aecae85c33f2ff5bc7e094c6449a6e"},{"type":"FIX","url":"https://github.com/team-alembic/ash_authentication/commit/d7c15c21d39c009206e010cd67e2d86370fe7a28"},{"type":"FIX","url":"https://github.com/team-alembic/ash_authentication/commit/2a2396af131ab67e2f445b805fecce8e6ca86c0e"},{"type":"PACKAGE","url":"https://hex.pm/packages/ash_authentication"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-17T13:26:04.340611555Z"}}