THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-777c-2fxx-qr28 (critical) — AshAuthentication vulnerable to OAuth2/OIDC account takeover via email-based user matching

[GHSA] GHSA-777c-2fxx-qr28 (critical) — AshAuthentication vulnerable to OAuth2/OIDC account takeover via email-based user matching

highgithub_advisoriesPublished 2026-08-25

GHSA-777c-2fxx-qr28 Severity: critical CVE: CVE-2026-49757

AshAuthentication vulnerable to OAuth2/OIDC account takeover via email-based user matching

### Summary

AshAuthentication's OAuth2 and OIDC family strategies matched the local user by email address rather than by the OpenID Connect `iss`/`sub` claim combination. A provider login presenting a victim's email (including an unverified, reuse

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-777c-2fxx-qr28