CVE-2026-81637 | team-alembic ash_authentication up to 4.14.0/5.0.0-rc.13 OAuth2 Strategy AshAuthentication.Strategy.OAuth2.Plug.callback session expiration

SecurityVulns

A vulnerability identified as critical has been detected in team-alembic ash_authentication up to 4.14.0/5.0.0-rc.13. The affected element is the function AshAuthentication.Strategy.OAuth2.Plug.callback of the component OAuth2 Strategy. Performing a manipulation results in session expiration.

This vulnerability is identified as CVE-2026-81637. The attack can be initiated remotely. There is not any exploit available.

You should upgrade the affected component.VulDB Recent EntriesRead More