Team-Alembic Ash Authentication
16 known vulnerabilities in Team-Alembic Ash Authentication, 6 critical, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-86688 CVSS 7.4 high Session Fixation vulnerability in team-alembic ash_authentication allows an attacker who can plant a session identifier in a victim's…
- CVE-2026-76949 CVSS 9.1 critical Authentication Bypass by Spoofing vulnerability in team-alembic ash_authentication allows an attacker who can plant a remember-me cookie…
- CVE-2026-91039 CVSS 9.1 critical Authentication Bypass by Spoofing vulnerability in team-alembic ash_authentication allows an attacker who operates one identity-provider…
- CVE-2026-88952 CVSS 9.1 critical Improper Authentication vulnerability in team-alembic AshAuthentication allows an attacker to be signed in as another user by linking an…
- CVE-2026-86533 CVSS 9.1 critical Insufficient Session Expiration vulnerability in team-alembic AshAuthentication and AshAuthentication Phoenix allows a revoked session to…
- CVE-2026-86522 CVSS 6.3 medium Improper Output Neutralization for Logs vulnerability in team-alembic AshAuthentication allows an unauthenticated attacker to forge…
- CVE-2026-85500 CVSS 9.1 critical Authentication Bypass by Primary Weakness vulnerability in team-alembic AshAuthentication allows an unconfirmed user to obtain a session…
- CVE-2026-82761 CVSS 9.1 critical Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in team-alembic AshAuthentication allows an attacker holding a leaked…
- CVE-2026-82760 CVSS 8.2 high Inefficient Algorithmic Complexity vulnerability in team-alembic AshAuthentication allows an unauthenticated attacker to exhaust CPU and…
- CVE-2026-82759 CVSS 1.8 low Use of a One-Way Hash with a Predictable Salt vulnerability in team-alembic AshAuthentication allows readers of the audit store to recover…
- CVE-2026-82723 CVSS 1.8 low Insertion of Sensitive Information into Log File vulnerability in team-alembic AshAuthentication allows disclosure of user password…
- CVE-2026-82685 CVSS 7.6 high Authorization Bypass Through User-Controlled Key vulnerability in team-alembic AshAuthentication allows an authenticated attacker to…
- CVE-2026-81637 CVSS 2.3 low Insufficient Session Expiration vulnerability in team-alembic AshAuthentication allows an attacker who obtains a victim's OAuth2 state…
- CVE-2026-81632 CVSS 7.2 high Use of HTTP Request With Sensitive Query String vulnerability in team-alembic AshAuthenticationPhoenix allows someone able to read access…
- CVE-2026-80218 CVSS 7.6 high Improper Authentication vulnerability in team-alembic AshAuthentication allows an attacker holding a sign-in token for one authenticated…
- CVE-2026-78223 CVSS 6.9 medium Improper Verification of Cryptographic Signature vulnerability in team-alembic AshAuthentication allows a caller of the token revocation…