CVE-2026-88952
Improper Authentication vulnerability in team-alembic AshAuthentication allows an attacker to be signed in as another user by linking an OAuth2 identity to an account that is not theirs.
AshAuthentication.Strategy.OAuth2.UserResolver.resolve/3 matches an existing account using the register action's upsert_identity keys, then gates linking the incoming provider identity to it on email_trusted?/2, which reads only the provider's email_verified boolean and never compares the provider's email value with the matched account's email.
Leer descripción completaMostrar menos
That gate assumes the account was matched by its email field, so under any other upsert_identity it is vacuous and an attacker presenting their own verified email is attached to, and issued a session for, an account matched on some other attribute. The same unguarded gate applies in OAuth2.SignInPreparation on the registration_enabled? false path, where the account is matched by the sign-in action's read filter instead. The upsert also rewrites the matched account's email to the attacker's address, so later account recovery reaches the attacker rather than the owner.
This issue affects ash_authentication: from 4.14.0 before 4.15.0 and from 5.0.0-rc.10 before 5.0.0-rc.14.
CVSS
- Versión: 4.0
- Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Puntuación base: 9.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.75%
- Percentil entre todas las CVEs puntuadas: 53
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1190Exploit Public-Facing Applicationinitial access85 % - Impacto principal
T1078Valid Accountsstealth · persistence · privilege escalation · initial access90 % - Impacto secundario
T1556Modify Authentication Processdefense impairment · persistence · credential access75 %
AV:N sin autenticación previa permite explotar OAuth2 para assumir sesiones ajenas. El atacante vincula su identidad verificada a cuenta ajena, obtiene sesión activa (T1078) y controla recuperación de cuenta reescribiendo email (T1556).
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-287
Referencias
- https://cna.erlef.org/cves/CVE-2026-88952.html
- https://github.com/team-alembic/ash_authentication/commit/2bd630eef8b7c8ae1e90e8fd43ba12fbc7e256ba
- https://github.com/team-alembic/ash_authentication/commit/42edcd8ebb13fafbb168f12591d7518ce0611fec
- https://github.com/team-alembic/ash_authentication/commit/64530644f9b37ebb76ca14aeb83a77597a0034b7
- https://github.com/team-alembic/ash_authentication/commit/738bf9f32f2aa0d1bb92ce9ca5c2476cb5710459
- https://github.com/team-alembic/ash_authentication/security/advisories/GHSA-wc6x-276q-jrf9
- https://osv.dev/vulnerability/EEF-CVE-2026-88952
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-88952",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-88952",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2026-09-17T19:32:22.090404Z"
}
}
],
"cvssMetricV40": [
{
"type": "Secondary",
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
"cvssData": {
"Safety": "NOT_DEFINED",
"version": "4.0",
"Recovery": "NOT_DEFINED",
"baseScore": 9.1,
"Automatable": "NOT_DEFINED",
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"exploitMaturity": "NOT_DEFINED",
"providerUrgency": "NOT_DEFINED",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"privilegesRequired": "NONE",
"subIntegrityImpact": "NONE",
"vulnIntegrityImpact": "HIGH",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"vulnAvailabilityImpact": "NONE",
"availabilityRequirement": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"subConfidentialityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"confidentialityRequirement": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"vulnerabilityResponseEffort": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED"
}
}
]
},
"affected": [
{
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
"affectedData": [
{
"cpes": [
"cpe:2.3:a:team-alembic:ash_authentication:*:*:*:*:*:*:*:*"
],
"repo": "https://github.com/team-alembic/ash_authentication",
"vendor": "team-alembic",
"modules": [
"'Elixir.AshAuthentication.Strategy.OAuth2.UserResolver'",
"'Elixir.AshAuthentication.Strategy.OAuth2.SignInPreparation'",
"'Elixir.AshAuthentication.Strategy.OAuth2.IdentityChange'",
"'Elixir.AshAuthentication.Strategy.DynamicOidc.IdentityChange'"
],
"product": "ash_authentication",
"versions": [
{
"status": "affected",
"version": "4.14.0",
"lessThan": "4.15.0",
"versionType": "semver"
},
{
"status": "affected",
"version": "5.0.0-rc.10",
"lessThan": "5.0.0-rc.14",
"versionType": "semver"
}
],
"packageURL": "pkg:hex/ash_authentication",
"packageName": "ash_authentication",
"programFiles": [
"lib/ash_authentication/strategies/oauth2/user_resolver.ex",
"lib/ash_authentication/strategies/oauth2/sign_in_preparation.ex",
"lib/ash_authentication/strategies/oauth2/identity_change.ex",
"lib/ash_authentication/strategies/dynamic_oidc/identity_change.ex"
],
"collectionURL": "https://repo.hex.pm",
"defaultStatus": "unaffected",
"programRoutines": [
{
"name": "'Elixir.AshAuthentication.Strategy.OAuth2.UserResolver':resolve/3"
},
{
"name": "'Elixir.AshAuthentication.Strategy.OAuth2.UserResolver':email_trusted?/2"
},
{
"name": "'Elixir.AshAuthentication.Strategy.OAuth2.SignInPreparation':prepare/3"
},
{
"name": "'Elixir.AshAuthentication.Strategy.OAuth2.IdentityChange':change/3"
},
{
"name": "'Elixir.AshAuthentication.Strategy.DynamicOidc.IdentityChange':change/3"
}
]
},
{
"cpes": [
"cpe:2.3:a:team-alembic:ash_authentication:*:*:*:*:*:*:*:*"
],
"repo": "https://github.com/team-alembic/ash_authentication",
"vendor": "team-alembic",
"modules": [
"'Elixir.AshAuthentication.Strategy.OAuth2.UserResolver'",
"'Elixir.AshAuthentication.Strategy.OAuth2.SignInPreparation'",
"'Elixir.AshAuthentication.Strategy.OAuth2.IdentityChange'",
"'Elixir.AshAuthentication.Strategy.DynamicOidc.IdentityChange'"
],
"product": "ash_authentication",
"versions": [
{
"status": "affected",
"changes": [
{
"at": "738bf9f32f2aa0d1bb92ce9ca5c2476cb5710459",
"status": "unaffected"
},
{
"at": "2bd630eef8b7c8ae1e90e8fd43ba12fbc7e256ba",
"status": "unaffected"
}
],
"version": "64530644f9b37ebb76ca14aeb83a77597a0034b7",
"lessThan": "*",
"versionType": "git"
},
{
"status": "affected",
"changes": [
{
"at": "738bf9f32f2aa0d1bb92ce9ca5c2476cb5710459",
"status": "unaffected"
},
{
"at": "2bd630eef8b7c8ae1e90e8fd43ba12fbc7e256ba",
"status": "unaffected"
}
],
"version": "42edcd8ebb13fafbb168f12591d7518ce0611fec",
"lessThan": "*",
"versionType": "git"
}
],
"packageURL": "pkg:github/team-alembic/ash_authentication",
"packageName": "team-alembic/ash_authentication",
"programFiles": [
"lib/ash_authentication/strategies/oauth2/user_resolver.ex",
"lib/ash_authentication/strategies/oauth2/sign_in_preparation.ex",
"lib/ash_authentication/strategies/oauth2/identity_change.ex",
"lib/ash_authentication/strategies/dynamic_oidc/identity_change.ex"
],
"collectionURL": "https://github.com",
"defaultStatus": "unaffected",
"programRoutines": [
{
"name": "'Elixir.AshAuthentication.Strategy.OAuth2.UserResolver':resolve/3"
},
{
"name": "'Elixir.AshAuthentication.Strategy.OAuth2.UserResolver':email_trusted?/2"
},
{
"name": "'Elixir.AshAuthentication.Strategy.OAuth2.SignInPreparation':prepare/3"
},
{
"name": "'Elixir.AshAuthentication.Strategy.OAuth2.IdentityChange':change/3"
},
{
"name": "'Elixir.AshAuthentication.Strategy.DynamicOidc.IdentityChange':change/3"
}
]
}
]
}
],
"published": "2026-09-17T15:16:56.290",
"references": [
{
"url": "https://cna.erlef.org/cves/CVE-2026-88952.html",
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
},
{
"url": "https://github.com/team-alembic/ash_authentication/commit/2bd630eef8b7c8ae1e90e8fd43ba12fbc7e256ba",
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
},
{
"url": "https://github.com/team-alembic/ash_authentication/commit/42edcd8ebb13fafbb168f12591d7518ce0611fec",
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
},
{
"url": "https://github.com/team-alembic/ash_authentication/commit/64530644f9b37ebb76ca14aeb83a77597a0034b7",
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
},
{
"url": "https://github.com/team-alembic/ash_authentication/commit/738bf9f32f2aa0d1bb92ce9ca5c2476cb5710459",
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
},
{
"url": "https://github.com/team-alembic/ash_authentication/security/advisories/GHSA-wc6x-276q-jrf9",
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
},
{
"url": "https://osv.dev/vulnerability/EEF-CVE-2026-88952",
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
"description": [
{
"lang": "en",
"value": "CWE-287"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Improper Authentication vulnerability in team-alembic AshAuthentication allows an attacker to be signed in as another user by linking an OAuth2 identity to an account that is not theirs.\n\nAshAuthentication.Strategy.OAuth2.UserResolver.resolve/3 matches an existing account using the register action's upsert_identity keys, then gates linking the incoming provider identity to it on email_trusted?/2, which reads only the provider's email_verified boolean and never compares the provider's email value with the matched account's email. That gate assumes the account was matched by its email field, so under any other upsert_identity it is vacuous and an attacker presenting their own verified email is attached to, and issued a session for, an account matched on some other attribute. The same unguarded gate applies in OAuth2.SignInPreparation on the registration_enabled? false path, where the account is matched by the sign-in action's read filter instead. The upsert also rewrites the matched account's email to the attacker's address, so later account recovery reaches the attacker rather than the owner.\n\nThis issue affects ash_authentication: from 4.14.0 before 4.15.0 and from 5.0.0-rc.10 before 5.0.0-rc.14."
}
],
"lastModified": "2026-09-18T18:16:18.527",
"sourceIdentifier": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
}