A vulnerability has been found in team-alembic ash_authentication up to 4.13.x and classified as critical. This issue affects some unknown processing. This manipulation of the argument email causes authentication bypass by spoofing.
This vulnerability is handled as CVE-2026-49757. It is possible to launch the attack on the local host. There is not any exploit available.
The affected component should be upgraded.