Critical OAuth2/OIDC Account Takeover Vulnerability in AshAuthentication
A critical vulnerability (CVE-2026-49757, CVSS 9.2) in AshAuthentication's OAuth2 and OIDC strategies allows unauthenticated remote account takeover via email-based user matching. The vulnerability affects applications using AshAuthentication with OAuth2/OIDC configurations that do not strictly verify email ownership. An attacker can register an account with a victim's email on a vulnerable provider, then gain full local privileges through a standard OAuth flow.