« Volver al listado

Alembic

Alembic ASH Authentication: vulnerabilidades y CVE

Alembic ASH Authentication tiene 21 vulnerabilidades publicadas, 19 de ellas en los últimos 12 meses. 7 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE21
Últimos 12 meses19
Críticas7
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-86688Alta (7.4)0.74%—17 sept 2026
Session Fixation vulnerability in team-alembic ash_authentication allows an attacker who can plant a session identifier in a victim's browser to hold an authenticated session once that victim signs in.…
CVE-2026-76949Crítica (9.1)0.77%—17 sept 2026
Authentication Bypass by Spoofing vulnerability in team-alembic ash_authentication allows an attacker who can plant a remember-me cookie in a victim's browser to replace that victim's authenticated session with one for…
CVE-2026-91039Crítica (9.1)0.66%—17 sept 2026
Authentication Bypass by Spoofing vulnerability in team-alembic ash_authentication allows an attacker who operates one identity-provider connection of a dynamic_oidc strategy to be signed in as a local user established…
CVE-2026-88952Crítica (9.1)0.75%—17 sept 2026
Improper Authentication vulnerability in team-alembic AshAuthentication allows an attacker to be signed in as another user by linking an OAuth2 identity to an account that is not theirs.…
CVE-2026-86533Crítica (9.1)0.91%—17 sept 2026
Insufficient Session Expiration vulnerability in team-alembic AshAuthentication and AshAuthentication Phoenix allows a revoked session to remain fully authenticated. A resource configured with session_identifier :jti…
CVE-2026-86522Media (6.3)0.74%—17 sept 2026
Improper Output Neutralization for Logs vulnerability in team-alembic AshAuthentication allows an unauthenticated attacker to forge application log entries by submitting a password reset identity containing newlines or…
CVE-2026-85500Crítica (9.1)0.77%—17 sept 2026
Authentication Bypass by Primary Weakness vulnerability in team-alembic AshAuthentication allows an unconfirmed user to obtain a session, defeating a mandatory email confirmation requirement.…
CVE-2026-82761Crítica (9.1)0.56%—17 sept 2026
Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in team-alembic AshAuthentication allows an attacker holding a leaked magic link to replay its single-use token and authenticate as the target subject. A…
CVE-2026-82760Alta (8.2)0.74%—17 sept 2026
Inefficient Algorithmic Complexity vulnerability in team-alembic AshAuthentication allows an unauthenticated attacker to exhaust CPU and memory via an oversized base62 segment in a submitted API key.…
CVE-2026-82759Baja (1.8)0.14%—17 sept 2026
Use of a One-Way Hash with a Predictable Salt vulnerability in team-alembic AshAuthentication allows readers of the audit store to recover the client IP addresses that the audit log add-on's :hash privacy mode is meant…
CVE-2026-82723Baja (1.8)0.18%—17 sept 2026
Insertion of Sensitive Information into Log File vulnerability in team-alembic AshAuthentication allows disclosure of user password digests to readers of the audit store. The audit_log add-on builds each entry's…
CVE-2026-82685Alta (7.6)0.66%—17 sept 2026
Authorization Bypass Through User-Controlled Key vulnerability in team-alembic AshAuthentication allows an authenticated attacker to overwrite and confirm another user's email address, and so take over that account. A…
CVE-2026-81637Baja (2.3)0.61%—17 sept 2026
Insufficient Session Expiration vulnerability in team-alembic AshAuthentication allows an attacker who obtains a victim's OAuth2 state value to replay the callback and sign that victim into an attacker-controlled…
CVE-2026-81632Alta (7.2)0.21%—17 sept 2026
Use of HTTP Request With Sensitive Query String vulnerability in team-alembic AshAuthenticationPhoenix allows someone able to read access logs, proxy logs or browser history to recover a single-use sign-in token and…
CVE-2026-80218Alta (7.6)0.64%—17 sept 2026
Improper Authentication vulnerability in team-alembic AshAuthentication allows an attacker holding a sign-in token for one authenticated resource to be signed in as a user of a different resource.…
CVE-2026-78223Media (6.9)0.44%—17 sept 2026
Improper Verification of Cryptographic Signature vulnerability in team-alembic AshAuthentication allows a caller of the token revocation action to neutralise a revocation or write arbitrary rows into the token resource.…
CVE-2026-66882Baja (2.1)0.75%—25 ago 2026
Improper Neutralization of Input During Web Page Generation (XSS) vulnerability in team-alembic AshAuthentication allows reflected cross-site scripting via the confirmation and magic link interaction forms. When a…
CVE-2026-65633Alta (7.6)0.58%—25 ago 2026
Improper Authentication vulnerability in team-alembic AshAuthentication allows purpose-limited JWTs to be replayed as full bearer API credentials when a resource uses stateless bearer-token verification. The…
CVE-2026-49757Crítica (9.2)0.68%—15 jun 2026
Authentication Bypass by Spoofing vulnerability in team-alembic AshAuthentication allows account takeover of local users via OAuth2/OIDC sign-in. AshAuthentication's OAuth2 and OIDC family strategies matched the local…
CVE-2025-32782Media (5.3)0.31%—15 abr 2025
Ash Authentication provides authentication for the Ash framework. The confirmation flow for account creation currently uses a GET request triggered by clicking a link sent via email. Some email clients and security…
CVE-2025-25202Media (6.3)0.31%—11 feb 2025
Ash Authentication is an authentication framework for Elixir applications. Applications which have been bootstrapped by the igniter installer present since AshAuthentication v4.1.0 and who have used the magic link…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application8
  2. T1078 Valid Accounts6
  3. T1078.001 Default Accounts4
  4. T1203 Exploitation for Client Execution2
  5. T1210 Exploitation of Remote Services2
  6. T1068 Exploitation for Privilege Escalation1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.