CVE-2026-80218 | team-alembic ash_authentication up to 3.10.5/4.14.x/5.0.0-rc.0/5.0.0-rc.13 SignInWithTokenPreparation improper authentication

SecurityVulns

A vulnerability described as critical has been identified in team-alembic ash_authentication up to 3.10.5/4.14.x/5.0.0-rc.0/5.0.0-rc.13. The affected element is the function AshAuthentication.Strategy.Password.SignInWithTokenPreparation.extract_primary_keys_from_subject of the component SignInWithTokenPreparation. Executing a manipulation can lead to improper authentication.

This vulnerability is registered as CVE-2026-80218. It is possible to launch the attack remotely. No exploit is available.

Upgrading the affected component is recommended.VulDB Recent EntriesRead More