External risk intelligence

AshAuthentication Magic Link Replay Vulnerability.

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-82761

The vulnerability affects an authentication mechanism (magic links) used for user sign-in. Authentication portals and identity management services are public-facing by design in normal use to allow users to access web applications and services over the internet.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability exists in the authentication system, specifically concerning the use of magic links. This issue allows an attacker with a compromised magic link to authenticate as another user due to a race condition in how the link's single-use token is validated and consumed. The primary concern is to confirm if this authentication technology is in use and assess potential exposure.

  • Replay of single-use magic links.
  • Confirms potential exposure of authentication technology.
  • Verify if magic links are used in your environment.

Attack Path

How an attacker could exploit the issue

An attacker with a previously leaked magic link can exploit a race condition to bypass authentication. By quickly replaying the single-use token from the magic link before it's revoked, an attacker can successfully sign in as the intended user. This vulnerability arises because the system checks the token's validity and revokes it after the sign-in process has already completed, allowing multiple concurrent attempts with the same token to succeed.

  • Leaked magic link is required.
  • Race condition during token redemption.
  • Unauthorized account access.

Live Threat

Current exploitation, exposure, and threat context

A Time-of-check Time-of-use (TOCTOU) race condition vulnerability in AshAuthentication allows an attacker with a leaked magic link to replay its single-use token and authenticate as the target user. This occurs because the system checks the token's validity and then consumes it in separate steps, creating a small window where concurrent requests can all succeed. When supported by the advisory, this could affect user account access and session tokens.

  • User account access and session tokens.
  • Concurrent requests to replay tokens.
  • Unauthorized account access and session hijack.

Operational Fix

Recommended remediation, mitigation, and detection steps

The critical time-of-check to time-of-use (TOCTOU) race condition in AshAuthentication's magic link handling can allow an attacker with a leaked token to impersonate users. Teams responsible for identity and access management, application platforms, or critical user-facing services should prioritize identifying all instances of the affected authentication components, assessing their exposure, and planning for remediation. The immediate first step involves locating the technology, confirming its reachability and business criticality, and identifying the accountable owner to develop a risk-based remediation plan.

  • Application or platform owners should own the issue.
  • Verify if magic link sign-in is in use.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the ash_authentication software?

AshAuthentication is an authentication framework for Elixir-based applications. It provides pre-built strategies, like magic links, to simplify secure user sign-in and identity management without requiring developers to write complex authentication logic from scratch.

What does CWE-367 mean for CVE-2026-82761?

CWE-367 refers to a Time-of-check Time-of-use (TOCTOU) race condition. In this CVE, the software verifies that a magic link token is valid but fails to lock it before finalizing the login. This creates a tiny window where multiple requests using the same token can be processed simultaneously before the system marks it as used.

How can an attacker trigger this vulnerability?

An attacker must first obtain a legitimate, leaked magic link meant for another user. They then trigger the flaw by sending multiple concurrent sign-in requests using that same token. It is not triggered by standard usage where a user clicks a link once; the vulnerability relies on the race condition created by rapid, simultaneous submissions.

Is my system at risk according to Halo Surface Signal?

Halo Surface Signal indicates a high likelihood of concern because authentication portals using magic links are typically internet-facing by design. Since these services must remain reachable to allow users to sign in, any application utilizing the affected AshAuthentication versions is likely exposed to remote attackers.

How do I start responding to this CVE?

First, identify if your applications use the AshAuthentication library and specifically if the magic link strategy is enabled. Once located, verify the version in use against the affected ranges provided in the advisory. Contact your application development team to confirm usage and prioritize updates to a non-vulnerable version.

References