A critical vulnerability, CVE-2026-49757 (CVSS 9.2), allows authentication bypass and account takeover in team-alembic's AshAuthentication Elixir library during OAuth2/OIDC federated sign-in. Vulnerable deployments may associate a login with an existing local account based on a mutable, unverified email claim instead of a stable issuer-and-subject identity, enabling an attacker using a weak or attacker-controlled identity provider to impersonate a victim.
The issue affects AshAuthentication versions 0.1.0 through versions before 4.14.0, and 5.0.0-rc.0 through versions before 5.0.0-rc.10; upgrades to 4.14.0 or 5.0.0-rc.10 remediate the flaw. Organizations using OAuth2/OIDC should verify durable identity mappings through identity_resource and avoid trusting mutable email claims for account linking. A public proof of concept is available, although active exploitation has not been observed.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
The public advisory and CVE-2026-49757 identifier were released, describing a critical flaw that could let attackers impersonate users when vulnerable applications matched federated logins using unverified email claims.
team-alembic published AshAuthentication 4.14.0 and 5.0.0-rc.10 to fix an OAuth2/OIDC authentication-bypass issue. The releases require identity_resource configuration and correct identity-record persistence for stable provider identity mapping.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
cvereports.com
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.