{"id":"CVE-2026-91039","summary":"dynamic_oidc identities are not namespaced by connection in ash_authentication, allowing cross-connection account takeover","details":"Authentication Bypass by Spoofing vulnerability in team-alembic ash_authentication allows an attacker who operates one identity-provider connection of a dynamic_oidc strategy to be signed in as a local user established through a different connection.\n\nThe strategy is meant to keep each connection in its own identity namespace by writing every UserIdentity row's strategy field as \"\u003cname\u003e/\u003cconnection_id\u003e\", but that namespacing never takes effect. __connection_id__ is populated only on the ephemeral runtime struct built per request in dynamic_oidc/plug.ex, and DynamicOidc.IdentityChange.change/3 re-fetches the strategy from the compile-time DSL through Info.strategy_for_action, yielding the persisted struct whose __connection_id__ is its defstruct default of nil. OAuth2.identity_strategy_name/1 therefore falls back to the bare strategy name for both the identity write and the reads in oauth2/user_resolver.ex and oauth2/sign_in_preparation.ex. Since the identity resource's unique key is (uid, strategy), one row exists per sub across every connection, and the identity-match branch runs before any email check. Neither strategy handles iss, so nothing else distinguishes the issuers: OpenID Connect Core section 5.7 makes sub unique only within an issuer, so two connections numbering subjects independently share one subject space.\n\nThis issue affects ash_authentication: from 5.0.0-rc.10 before 5.0.0-rc.14.","aliases":["EEF-CVE-2026-91039","GHSA-73j9-m294-fvv9"],"modified":"2026-09-20T11:30:34.910649684Z","published":"2026-09-17T15:19:15.994Z","database_specific":{"cna_assigner":"EEF","cwe_ids":["CWE-290"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/91xxx/CVE-2026-91039.json","unresolved_ranges":[{"extracted_events":[{"introduced":"64530644f9b37ebb76ca14aeb83a77597a0034b7"},{"fixed":"73ad16e452670bbf843550a13361bd41e72ad964"}],"source":"AFFECTED_FIELD"}]},"references":[{"type":"WEB","url":"https://cna.erlef.org/cves/CVE-2026-91039.html"},{"type":"WEB","url":"https://github.com"},{"type":"WEB","url":"https://osv.dev/vulnerability/EEF-CVE-2026-91039"},{"type":"WEB","url":"https://repo.hex.pm"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/91xxx/CVE-2026-91039.json"},{"type":"ADVISORY","url":"https://github.com/team-alembic/ash_authentication/security/advisories/GHSA-73j9-m294-fvv9"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-91039"},{"type":"FIX","url":"https://github.com/team-alembic/ash_authentication/commit/64530644f9b37ebb76ca14aeb83a77597a0034b7"},{"type":"FIX","url":"https://github.com/team-alembic/ash_authentication/commit/73ad16e452670bbf843550a13361bd41e72ad964"},{"type":"PACKAGE","url":"https://github.com/team-alembic/ash_authentication"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/team-alembic/ash_authentication","events":[{"introduced":"8fa0d9823fbef04aaab517e7ea0f4b17976f1502"},{"fixed":"fea75958a081ed337ceb578396174039694c48df"},{"fixed":"64530644f9b37ebb76ca14aeb83a77597a0034b7"},{"fixed":"73ad16e452670bbf843550a13361bd41e72ad964"}],"database_specific":{"extracted_events":[{"introduced":"5.0.0-rc.10"},{"fixed":"5.0.0-rc.14"}],"source":["DESCRIPTION","REFERENCES"]}}],"versions":["v5.0.0-rc.13","v5.0.0-rc.12","v5.0.0-rc.11","v5.0.0-rc.10"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-91039.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"}]}