CVE-2026-86522
Improper Output Neutralization for Logs vulnerability in team-alembic AshAuthentication allows an unauthenticated attacker to forge application log entries by submitting a password reset identity containing newlines or control characters. AshAuthentication.Strategy.Password.RequestPasswordReset.run/3 interpolates the identity argument, the email or username taken straight from the reset request, into its Logger.warning/1 heredocs without escaping, truncating or type-restricting it. The resource logged beside it is passed through inspect/1, which would have neutralized the value. A newline in the identity therefore ends the log record, and everything after it is written as a line of its own, so an attacker chooses the severity tag and the content of entries that appear to have come from the application. This issue affects ash_authentication: from 4.2.0 before 4.15.0 and from 5.0.0-rc.0 before 5.0.0-rc.14.
What this means for your business
What to do
- 1Ask your IT team or provider whether any of your systems use the affected product.
- 2If you do, follow the vendor's guidance. No patch reference has been published yet.
Not sure if your company is exposed?
Fastnexa’s certified penetration testers can check whether attackers could use this flaw, or others like it, against your websites, apps and network. The full test is free for our first 10 founding clients until 31 December 2026.
Scoring
- CVSS
- Not yet scored
- CVSS v4
- 6.3
- Weakness
- CWE-117
- Assigned by
- 6b3ad84c-e1a6-4bf7-a703-f496b71e49db
Dates
- Published
- 2026-09-17
- Last modified
- 2026-09-18
- Sources
- NVD
References
- https://cna.erlef.org/cves/CVE-2026-86522.html
- https://github.com/team-alembic/ash_authentication/commit/3954f277929712755aef57a4a3a821688f121316
- https://github.com/team-alembic/ash_authentication/commit/57c7cc3236bef0fa9da19cb315414f216488866d
- https://github.com/team-alembic/ash_authentication/commit/fd19358bf0eee53ef13dcf17cc499bd4fb393981
- https://github.com/team-alembic/ash_authentication/security/advisories/GHSA-wg7g-r393-vr3g
- https://osv.dev/vulnerability/EEF-CVE-2026-86522