CVE-2026-82759
CVE-2026-82759 is a low-severity vulnerability with a CVSS 4.0 base score of 1.8. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-760.
Key facts
- Severity: Low (CVSS 4.0 base score 1.8)
- EPSS exploit prediction: 0% (3rd percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-760
- Published:
- Last modified:
Description
Use of a One-Way Hash with a Predictable Salt vulnerability in team-alembic AshAuthentication allows readers of the audit store to recover the client IP addresses that the audit log add-on's :hash privacy mode is meant to pseudonymise. AshAuthentication.AddOn.AuditLog.IpPrivacy.hash_ip/1 computes a single unkeyed :crypto.hash(:sha256, salt <> ip) and truncates the result to 16 hexadecimal characters. The salt is read from the :audit_log_ip_salt or :secret application config keys, and falls back to the constant "default-salt-change-in-production" published in the library source when neither is set, with nothing warning that the default is in use. The IPv4 space is only 2^32 values and SHA-256 is fast, so the whole hash table is precomputable and every stored value maps back to its source address. Truncating to 16 characters does not help, and even a configured salt leaves the hash cheap enough to enumerate once it leaks. This issue affects ash_authentication: from 4.12.0 before 4.15.0 and from 5.0.0-rc.0 before 5.0.0-rc.14.
Frequently asked questions
- What is CVE-2026-82759?
- Use of a One-Way Hash with a Predictable Salt vulnerability in team-alembic AshAuthentication allows readers of the audit store to recover the client IP addresses that the audit log add-on's :hash privacy mode is meant to pseudonymise. AshAuthentication.AddOn.AuditLog.IpPrivacy.hash_ip/1 computes a single unkeyed :crypto.hash(:sha256, salt <> ip) and truncates the result to 16 hexadecimal characters. The salt is read from the :audit_log_ip_salt or :secret application config keys, and falls back to the constant "default-salt-change-in-production" published in the library source when neither is set, with nothing warning that the default is in use. The IPv4 space is only 2^32 values and SHA-256 is fast, so the whole hash table is precomputable and every stored value maps back to its source address. Truncating to 16 characters does not help, and even a configured salt leaves the hash cheap enough to enumerate once it leaks. This issue affects ash_authentication: from 4.12.0 before 4.15.0 and from 5.0.0-rc.0 before 5.0.0-rc.14.
- How severe is CVE-2026-82759?
- CVE-2026-82759 has a CVSS 4.0 base score of 1.8, rated low severity.
- Is CVE-2026-82759 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (3rd percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2026-82759?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2026-82759 published?
- CVE-2026-82759 was published on 2026-09-17 and last updated on 2026-09-18.
References
- https://cna.erlef.org/cves/CVE-2026-82759.html
- https://github.com/team-alembic/ash_authentication/commit/255cfc9c0e511b7e0de39f8b3d676ae994fae06c
- https://github.com/team-alembic/ash_authentication/commit/c3a6d5fe0d4fd383ea81b0402db0a96638479478
- https://github.com/team-alembic/ash_authentication/commit/d8a9c4b6bde828fdc8346198d5e4f588b5937541
- https://github.com/team-alembic/ash_authentication/security/advisories/GHSA-cgqj-pcpq-xhfm
- https://osv.dev/vulnerability/EEF-CVE-2026-82759
Other CWE-760 vulnerabilities
- CVE-2024-13951 — High (CVSS 7.6): One way hash with predictable salt vulnerabilities in ASPECT may expose sensitive information to a potential…
- CVE-2026-46749 — High (CVSS 7.5): A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected application uses a…
- CVE-2024-38881 — High (CVSS 7.5): An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions,…
- CVE-2023-22599 — High (CVSS 7.0): InHand Networks InRouter 302, prior to version IR302 V3.5.56, and InRouter 615, prior to version…
- CVE-2025-9290 — Medium (CVSS 5.9): An authentication weakness was identified in Omada Controllers, Gateways and Access Points, controller-device adoption…
- CVE-2020-28214 — Medium (CVSS 5.5): A CWE-760: Use of a One-Way Hash with a Predictable Salt vulnerability exists in Modicon M221 (all references, all…