Answer in brief
CVE-2026-86533 records a Unknown severity vulnerability in Revoked session accepted because the session jti is never checked in AshAuthentication and AshAuthentication Phoenix. The current sources do not mark it as known exploited. The current feed maps team-alembic/ash_authentication (generic), team-alembic/ash_authentication (generic), team-alembic/ash_authentication_phoenix (generic), team-alembic/ash_authentication_phoenix (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps team-alembic/ash_authentication (generic), team-alembic/ash_authentication (generic), team-alembic/ash_authentication_phoenix (generic), team-alembic/ash_authentication_phoenix (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| team-alembic/ash_authenticationgeneric | >=4.9.1 <4.15.0 || >=5.0.0-rc.0 <5.0.0-rc.14 | 4.15.0, 5.0.0-rc.14 |
| team-alembic/ash_authenticationgeneric | >=fcaeb73f76f8f2e9aef8bf637690d2a20dd97596 <* | * |
| team-alembic/ash_authentication_phoenixgeneric | >=2.10.0 <2.17.4 || >=3.0.0-rc.0 <* | 2.17.4, * |
| team-alembic/ash_authentication_phoenixgeneric | >=a3253fb4fc7145aeb403537af1c24d3a8d51ffb1 <f7ab005a2aac09707a25521653c94893d328cc52 || >=0135217e34e621dac79ae3d9559aeee49304b0aa <f7ab005a2aac09707a25521653c94893d328cc52 | f7ab005a2aac09707a25521653c94893d328cc52 |
| team-alembic/ash_authentication_phoenixgeneric | >=2.10.0 <2.17.4 || >=3.0.0-rc.0 <3.0.0-rc.11 | 2.17.4, 3.0.0-rc.11 |
| team-alembic/ash_authentication_phoenixgeneric | >=a3253fb4fc7145aeb403537af1c24d3a8d51ffb1 <* || >=0135217e34e621dac79ae3d9559aeee49304b0aa <* | * |
Published upstream
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 17, 2026
Insufficient Session Expiration vulnerability in team-alembic AshAuthentication and AshAuthentication Phoenix allows a revoked session to remain fully authenticated. A resource configured with session_identifier :jti and require_token_presence_for_authentication? disabled stores its session value as <jti>:<subject>. The jti is there so that signing out can revoke that one session. Neither reader consults it: AshAuthentication.Plug.Helpers.authenticate_resource_from_session/4 and AshAuthentication.Phoenix.LiveSession.on_mount/4 both split the value with split_identifier/2, discard the jti and pass the bare subject to AshAuthentication.subject_to_user/3, which reloads the record. The token-presence branch of each function does check its token, calling AshAuthentication.TokenResource.Actions.get_token/3 with the jti and the purpose user. Because the revocation record is never read, neither its revoked state nor its expiry constrains the session, so a session captured before sign-out keeps working. This issue affects ash_authentication: from 4.9.1 before 4.15.0 and from 5.0.0-rc.0 before 5.0.0-rc.14; ash_authentication_phoenix: from 2.10.0 before 2.17.4 and from 3.0.0-rc.0 before 3.0.0-rc.11.
Quoted source text, attributed separately from HOL analysis.