CVE-2026-49757: CWE-290 Authentication Bypass by Spoofing in team-alembic ash_authentication
CVE-2026-49757 is a critical authentication bypass vulnerability in team-alembic's ash_authentication library affecting versions from 0.1.0 before 4.14.0 and from 5.0.0-rc.0 before 5.0.0-rc.10. The flaw allows an attacker to take over local user accounts via OAuth2/OIDC sign-in by matching users based on email rather than the required unique OpenID Connect iss/sub claims. This enables an unauthenticated attacker who can register an OAuth provider account with a victim's email to impersonate that victim and gain their privileges. The issue arises because email addresses, including unverified or reused ones, were used as unique identifiers instead of the stable iss/sub combination. The fix involves resolving users by the (strategy, sub) identity and only linking by email if the email_verified claim is trusted.
AI Analysis
Technical Summary
The vulnerability in ash_authentication stems from improper user identification during OAuth2/OIDC sign-in. Instead of using the OpenID Connect standard unique identifier (iss/sub claim), the system matched local users by email address, which can be spoofed or reused. This allowed attackers to bypass authentication by registering an OAuth provider account with a victim's email, including unverified emails, leading to full local account takeover. The fix changes the resolution logic to rely on the (strategy, sub) identity and conditionally link accounts by email only when the email_verified claim is trusted. Affected versions include 0.1.0 through before 4.14.0 and 5.0.0-rc.0 through before 5.0.0-rc.10.
Potential Impact
An unauthenticated attacker can gain full control over a victim's local user account by exploiting the authentication bypass. This results in account takeover and potentially unauthorized access to all privileges associated with the victim's account. The vulnerability undermines the integrity of the authentication process in affected versions of ash_authentication.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. The vendor has described a fix that changes user resolution to rely on the (strategy, sub) identity and only link accounts by email when the email_verified claim is trusted. Until an official fix is confirmed, users should monitor vendor communications for patches or updates addressing this issue.
CVE-2026-49757: CWE-290 Authentication Bypass by Spoofing in team-alembic ash_authentication
Description
CVE-2026-49757 is a critical authentication bypass vulnerability in team-alembic's ash_authentication library affecting versions from 0.1.0 before 4.14.0 and from 5.0.0-rc.0 before 5.0.0-rc.10. The flaw allows an attacker to take over local user accounts via OAuth2/OIDC sign-in by matching users based on email rather than the required unique OpenID Connect iss/sub claims. This enables an unauthenticated attacker who can register an OAuth provider account with a victim's email to impersonate that victim and gain their privileges. The issue arises because email addresses, including unverified or reused ones, were used as unique identifiers instead of the stable iss/sub combination. The fix involves resolving users by the (strategy, sub) identity and only linking by email if the email_verified claim is trusted.
CVSS v4.0
Score 9.2critical
Affected software
pkg:github/team-alembic/ash_authenticationcpe:2.3:a:team-alembic:ash_authentication:*:*:*:*:*:*:*:*Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in ash_authentication stems from improper user identification during OAuth2/OIDC sign-in. Instead of using the OpenID Connect standard unique identifier (iss/sub claim), the system matched local users by email address, which can be spoofed or reused. This allowed attackers to bypass authentication by registering an OAuth provider account with a victim's email, including unverified emails, leading to full local account takeover. The fix changes the resolution logic to rely on the (strategy, sub) identity and conditionally link accounts by email only when the email_verified claim is trusted. Affected versions include 0.1.0 through before 4.14.0 and 5.0.0-rc.0 through before 5.0.0-rc.10.
Potential Impact
An unauthenticated attacker can gain full control over a victim's local user account by exploiting the authentication bypass. This results in account takeover and potentially unauthorized access to all privileges associated with the victim's account. The vulnerability undermines the integrity of the authentication process in affected versions of ash_authentication.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. The vendor has described a fix that changes user resolution to rely on the (strategy, sub) identity and only link accounts by email when the email_verified claim is trusted. Until an official fix is confirmed, users should monitor vendor communications for patches or updates addressing this issue.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- EEF
- Date Reserved
- 2026-06-01T13:45:22.449Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a2fe9580b89be6888e98672
Added to database: 06/15/2026, 12:00:24 UTC
Last enriched: 06/22/2026, 15:20:45 UTC
Last updated: 07/13/2026, 07:47:29 UTC
Views: 149
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.