CVE-2026-86522 | team-alembic ash_authentication up to 4.14.x/5.0.0-rc.13 Password Reset identity neutralization

SecurityVulns

A vulnerability, which was classified as critical, has been found in team-alembic ash_authentication up to 4.14.x/5.0.0-rc.13. This impacts the function AshAuthentication.Strategy.Password.RequestPasswordReset.run of the component Password Reset. This manipulation of the argument identity causes improper neutralization.

This vulnerability appears as CVE-2026-86522. The attack may be initiated remotely. There is no available exploit.VulDB Recent EntriesRead More