CVE-2026-86688

Summary

Session Fixation vulnerability in team-alembic ash_authentication allows an attacker who can plant a session identifier in a victim's browser to hold an authenticated session once that victim signs in.

AshAuthentication.Plug.Helpers.store_in_session/2 writes the authenticated subject into the existing session with Plug.Conn.put_session/3 and never calls Plug.Conn.configure_session(renew: true), so the identifier the visitor arrived with carries into their authenticated session. Every authentication event reaches this one function: the default success/4 injected by AshAuthentication.Phoenix.Controller.using/1, the AuthController emitted by mix ash_authentication_phoenix.install, and remember-me auto-login. AshAuthentication.Phoenix.Plug.store_in_session/2 is a defdelegate to it. Logout does not close the window either, because clear_session/2 ends with Plug.Conn.clear_session/1, which clears session contents but leaves the identifier intact, so a planted identifier survives a logout-then-login cycle.

This issue affects ash_authentication: from 0.2.0 before 4.15.0 and from 5.0.0-rc.0 before 5.0.0-rc.14.

Affected Software

VendorProductVersion RangeStatus
team-alembicash_authentication0.2.0 < 4.15.0affected
team-alembicash_authentication5.0.0-rc.0 < 5.0.0-rc.14affected
team-alembicash_authenticationa939dde9b917c072cdf10c4b0913a9886a4b0231 < *affected

Weaknesses

  • CWE-384: CWE-384 Session Fixation

Workarounds

Call Plug.Conn.configure_session(conn, renew: true) in your own success/4 before store_in_session/2. This is a one-line change in application code and closes the controller sign-in path, though not remember-me auto-login, which does not pass through application code.

Add Plug.Conn.configure_session(conn, drop: true) at sign-out so a planted identifier does not survive a logout-then-login cycle.

References