CVE-2026-49757 is an authentication-bypass vulnerability in team-alembic AshAuthentication's OAuth2 and OIDC strategies. Affected versions resolve an existing local user by an email claim through an email-field upsert or application-defined sign-in filter, rather than binding the federated identity to the stable OpenID Connect issuer and subject identity pair. Because email claims can be unverified, mutable, reused, or reclaimed, a provider identity presenting a victim's email can be associated with and authenticated as the victim's local account. The corrected implementation resolves identities through a stored strategy-and-subject mapping in a user identity resource and permits email-based linking only when the provider's verified-email assertion is explicitly trusted.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository is a small standalone Python proof-of-concept for CVE-2026-49757 in AshAuthentication. It contains 4 files: a README, main PoC driver (exploit.py), and a supporting simulation module (vulnerable_handler.py), plus .gitignore. The exploit is not aimed at a live remote target by default; instead it models the vulnerable OAuth/OIDC account-linking logic locally using SQLite and demonstrates both exploitation and patched behaviors. Main capability: exploit.py walks through a full account takeover scenario where a victim account exists with email admin@target-app.com, the victim has a legitimate Google identity linked, and an attacker authenticates through a different provider (example: Keycloak) using the same email. The vulnerable handler resolves the account by email rather than by the stable identity pair (strategy, sub), silently updates the linked identity, and creates a session for the victim account. The script explicitly shows the resulting session token, user_id, email, and role, demonstrating privilege inheritance such as admin access. Repository structure and purpose: - exploit.py: interactive/non-interactive demonstration script with multiple phases. Phase 1 shows successful takeover using the vulnerable logic. Additional phases demonstrate fixed logic with reject, confirm, and trusted-email-verified behaviors. - vulnerable_handler.py: contains the simulated backend logic. It initializes SQLite tables for users and user_identities, implements VulnerableAuthHandler with email-based matching/upsert, and also includes fixed-handler logic (partially truncated in provided content) that uses safer identity resolution and policy enforcement. - README.md: documents the CVE, affected/patched versions, attack prerequisites, usage, and remediation concepts. Technical exploit behavior: the vulnerable code creates a unique index effectively keyed on json_extract(user_info, '$.email') and, during oauth_callback, searches existing identities by provider-supplied email. If a match exists, it updates uid/user_info/tokens for that identity and signs in the matched local user. If no identity exists but a local user with that email exists, it links the OAuth identity to that user and signs in. This demonstrates authentication bypass/spoofing via untrusted email claims from an OAuth/OIDC provider. No real command payload, shell, or malware behavior is present. The exploit outcome is session creation as the victim user, making this a realistic but educational PoC rather than a weaponized framework module.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Critical authentication-bypass and remote account-takeover vulnerability in team-alembic's ash_authentication Elixir package. A flawed OAuth2/OIDC identity-resolution path can match local accounts using mutable, unverified email claims rather than a stable issuer-and-subject identity mapping, enabling an attacker using a weak or attacker-controlled identity provider to impersonate an existing local user.
A critical authentication bypass/account takeover vulnerability in AshAuthentication's OAuth2/OIDC sign-in flow, caused by matching users by email instead of the OIDC iss/sub identity, allowing attackers to sign in as victims under certain conditions.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.