CVE-2026-86533

Source
https://cve.org/CVERecord?id=CVE-2026-86533
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-86533.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-86533
Aliases
Related
  • GHSA-m6x4-4gvp-xwjr
  • GHSA-w374-hvrx-66hg
Published
2026-09-17T13:09:37Z
Modified
2026-09-20T11:47:27Z
Severity
  • 9.1 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Revoked session accepted because the session jti is never checked in AshAuthentication and AshAuthentication Phoenix
Details

Insufficient Session Expiration vulnerability in team-alembic AshAuthentication and AshAuthentication Phoenix allows a revoked session to remain fully authenticated.

A resource configured with session_identifier :jti and require_token_presence_for_authentication? disabled stores its session value as :. The jti is there so that signing out can revoke that one session. Neither reader consults it: AshAuthentication.Plug.Helpers.authenticate_resource_from_session/4 and AshAuthentication.Phoenix.LiveSession.on_mount/4 both split the value with split_identifier/2, discard the jti and pass the bare subject to AshAuthentication.subject_to_user/3, which reloads the record. The token-presence branch of each function does check its token, calling AshAuthentication.TokenResource.Actions.get_token/3 with the jti and the purpose user. Because the revocation record is never read, neither its revoked state nor its expiry constrains the session, so a session captured before sign-out keeps working.

This issue affects ash_authentication: from 4.9.1 before 4.15.0 and from 5.0.0-rc.0 before 5.0.0-rc.14; ash_authentication_phoenix: from 2.10.0 before 2.17.4 and from 3.0.0-rc.0 before 3.0.0-rc.11.

Database specific
{
    "cna_assigner": "EEF",
    "cwe_ids": [
        "CWE-613"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/86xxx/CVE-2026-86533.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "fcaeb73f76f8f2e9aef8bf637690d2a20dd97596"
                },
                {
                    "fixed": "*"
                },
                {
                    "introduced": "2.10.0"
                },
                {
                    "fixed": "2.17.4"
                },
                {
                    "introduced": "3.0.0-rc.0"
                },
                {
                    "fixed": "3.0.0-rc.11"
                },
                {
                    "introduced": "a3253fb4fc7145aeb403537af1c24d3a8d51ffb1"
                },
                {
                    "fixed": "*"
                },
                {
                    "introduced": "0135217e34e621dac79ae3d9559aeee49304b0aa"
                },
                {
                    "fixed": "*"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/team-alembic/ash_authentication

Affected ranges

Type
GIT
Repo
https://github.com/team-alembic/ash_authentication
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "4.9.1"
        },
        {
            "fixed": "4.15.0"
        },
        {
            "introduced": "5.0.0-rc.0"
        },
        {
            "fixed": "5.0.0-rc.14"
        }
    ],
    "source": [
        "DESCRIPTION",
        "REFERENCES"
    ]
}
Type
GIT
Repo
https://github.com/team-alembic/ash_authentication_phoenix
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "2.10.0"
        },
        {
            "fixed": "2.17.4"
        },
        {
            "introduced": "3.0.0-rc.0"
        },
        {
            "fixed": "3.0.0-rc.11"
        }
    ],
    "source": [
        "DESCRIPTION",
        "REFERENCES"
    ]
}

Affected versions

2.*
2.17.0
3.*
3.0.0-rc.3
3.0.0-rc.8
5.*
5.0.0-rc.8
5.0.0-rc.9
v2.*
v2.10.0
v2.10.1
v2.10.2
v2.10.3
v2.10.4
v2.10.5
v2.11.0
v2.12.0
v2.12.1
v2.12.2
v2.13.0
v2.13.1
v2.14.0
v2.14.1
v2.15.0
v2.16.0
v2.17.1
v2.17.2
v2.17.3
v3.*
v3.0.0-rc.0
v3.0.0-rc.1
v3.0.0-rc.10
v3.0.0-rc.3
v3.0.0-rc.4
v3.0.0-rc.6
v3.0.0-rc.7
v3.0.0-rc.9
v4.*
v4.10.0
v4.11.0
v4.12.0
v4.13.0
v4.13.1
v4.13.2
v4.13.3
v4.13.4
v4.13.5
v4.13.6
v4.13.7
v4.14.0
v4.14.1
v4.14.2
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v4.9.5
v4.9.6
v4.9.7
v4.9.8
v4.9.9
v5.*
v5.0.0-rc.0
v5.0.0-rc.1
v5.0.0-rc.10
v5.0.0-rc.11
v5.0.0-rc.12
v5.0.0-rc.13
v5.0.0-rc.2
v5.0.0-rc.3
v5.0.0-rc.4
v5.0.0-rc.5
v5.0.0-rc.6
v5.0.0-rc.7

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-86533.json"