CVE-2026-78223
published 2026-09-17CVE-2026-78223: Improper Verification of Cryptographic Signature vulnerability in team-alembic AshAuthentication allows a caller of the token revocation action to neutralise a…
PriorityP341medium6.9CVSS 4.0
AVNACLATNPRNUINVCNVILVANSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.44%
36.1th percentile
Improper Verification of Cryptographic Signature vulnerability in team-alembic AshAuthentication allows a caller of the token revocation action to neutralise a revocation or write arbitrary rows into the token resource.
AshAuthentication.TokenResource.RevokeTokenChange.change/3 reads the :token argument and decodes it with AshAuthentication.Jwt.peek/1, which delegates to Joken.peek_claims/1 and performs no signature check, unlike Jwt.verify/4. The jti, exp and sub claims it returns are written straight onto the revocation record, guarded only by byte_size(token) > 0. Because expires_at derives from the attacker-chosen exp, a forged copy of a genuine token that keeps the real jti but backdates exp yields a revocation row that is already expired: expunge_expired removes it and the genuine token passes revoked? again. Arbitrary jti and sub values can be inserted the same way.
This issue affects ash_authentication: from 0.2.0 before 4.15.0 and from 5.0.0-rc.0 before 5.0.0-rc.14.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| team-alembic | ash_authentication | >= 0.2.0 < 4.15.0 | 4.15.0 |
| team-alembic | ash_authentication | >= 5.0.0-rc.0 < 5.0.0-rc.14 | 5.0.0-rc.14 |
| team-alembic | ash_authentication | >= a939dde9b917c072cdf10c4b0913a9886a4b0231 < * | * |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No advisories linked to this vulnerability.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://cna.erlef.org/cves/CVE-2026-78223.htmlhttps://github.com/team-alembic/ash_authentication/commit/344cebb12faf68e648d3283394073ba0c0f78459https://github.com/team-alembic/ash_authentication/commit/a939dde9b917c072cdf10c4b0913a9886a4b0231https://github.com/team-alembic/ash_authentication/commit/eb86353fe5a547c5ff5fd9af0e2c212518c31c9bhttps://github.com/team-alembic/ash_authentication/security/advisories/GHSA-mfwg-5cpf-px58https://osv.dev/vulnerability/EEF-CVE-2026-78223
2026-09-17
Published