{"id":"CVE-2026-86533","aliases":["GHSA-m6x4-4gvp-xwjr"],"url":"https://o3.security/vulnerability/CVE-2026-86533","summary":"Revoked session accepted because the session jti is never checked in AshAuthentication and AshAuthentication Phoenix","details":"## Summary\n\nInsufficient Session Expiration vulnerability in team-alembic AshAuthentication and AshAuthentication Phoenix allows a revoked session to remain fully authenticated.\n\nA resource configured with `session_identifier :jti` and `require_token_presence_for_authentication?` disabled stores its session value as `<jti>:<subject>`. The `jti` is there so that signing out can revoke that one session. Neither reader consults it: `AshAuthentication.Plug.Helpers.authenticate_resource_from_session/4` and `AshAuthentication.Phoenix.LiveSession.on_mount/4` both split the value with `split_identifier/2`, discard the `jti` and pass the bare subject to `AshAuthentication.subject_to_user/3`, which reloads the record. The token-presence branch of each function does check its token, calling `AshAuthentication.TokenResource.Actions.get_token/3` with the `jti` and the purpose `user`. Because the revocation record is never read, neither its revoked state nor its expiry constrains the session, so a session captured before sign-out keeps working.\n\nThis issue affects ash_authentication_phoenix: from 2.10.0 before 2.17.4 and from 3.0.0-rc.0 onward; ash_authentication: from 4.9.1 before 4.15.0 and from 5.0.0-rc.0 before 5.0.0-rc.14.","published":"2026-09-17T13:09:37.963Z","modified":"2026-09-17T13:15:04.054907186Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Hex","name":"ash_authentication_phoenix","fixedVersion":"2.17.4"},{"ecosystem":"Hex","name":"ash_authentication","fixedVersion":"4.15.0"}],"fix":{"url":"https://github.com/team-alembic/ash_authentication_phoenix/commit/f7ab005a2aac09707a25521653c94893d328cc52","label":"team-alembic/ash_authentication_phoenix@f7ab005"},"references":[{"type":"ADVISORY","url":"https://github.com/team-alembic/ash_authentication_phoenix/security/advisories/GHSA-m6x4-4gvp-xwjr"},{"type":"WEB","url":"https://cna.erlef.org/cves/CVE-2026-86533.html"},{"type":"ADVISORY","url":"https://github.com/team-alembic/ash_authentication/security/advisories/GHSA-w374-hvrx-66hg"},{"type":"WEB","url":"https://github.com/team-alembic/ash_authentication_phoenix/commit/a3253fb4fc7145aeb403537af1c24d3a8d51ffb1"},{"type":"WEB","url":"https://github.com/team-alembic/ash_authentication_phoenix/commit/0135217e34e621dac79ae3d9559aeee49304b0aa"},{"type":"FIX","url":"https://github.com/team-alembic/ash_authentication_phoenix/commit/f7ab005a2aac09707a25521653c94893d328cc52"},{"type":"WEB","url":"https://github.com/team-alembic/ash_authentication/commit/fcaeb73f76f8f2e9aef8bf637690d2a20dd97596"},{"type":"FIX","url":"https://github.com/team-alembic/ash_authentication/commit/a3f49f758f013d2ff086dd9c5ef2d94e921711b4"},{"type":"FIX","url":"https://github.com/team-alembic/ash_authentication/commit/e28e911caa9728d76329afdb0fb26742ffe4eeef"},{"type":"PACKAGE","url":"https://hex.pm/packages/ash_authentication_phoenix"},{"type":"PACKAGE","url":"https://hex.pm/packages/ash_authentication"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-17T13:15:04.054907186Z"}}