THREAT OPS › Threat News › [GHSA] GHSA-777c-2fxx-qr28 (critical) — AshAuthentication vulnerable to OAuth2/OIDC account takeover via email-based user matching
[GHSA] GHSA-777c-2fxx-qr28 (critical) — AshAuthentication vulnerable to OAuth2/OIDC account takeover via email-based user matching
GHSA-777c-2fxx-qr28 Severity: critical CVE: CVE-2026-49757
AshAuthentication vulnerable to OAuth2/OIDC account takeover via email-based user matching
### Summary
AshAuthentication's OAuth2 and OIDC family strategies matched the local user by email address rather than by the OpenID Connect `iss`/`sub` claim combination. A provider login presenting a victim's email (including an unverified, reuse
MITRE ATT&CK techniques
Indicators of compromise
- c5f589058e04239263f50a1430eb17ea6d5dd1a2sha1
- 728b8d28c1b5f465fa1116ef044a815300fc733dsha1
- 64530644f9b37ebb76ca14aeb83a77597a0034b7sha1
- CVE-2026-49757cve
Original source: https://github.com/advisories/GHSA-777c-2fxx-qr28