CVE-2026-49757 - OAuth2/OIDC account takeover in AshAuthentication via email-based user matching
CVE ID :CVE-2026-49757 Published : June 15, 2026, 12:16 p.m. | 52 minutes ago Description :Authentication Bypass by Spoofing vulnerability in team-alembic AshAuthentication allows account takeover of local users via OAuth2/OIDC sign-in. AshAuthentication's OAuth2 and OIDC family strategies...