Authorization Flaw in Ash Project Affects User Data Privacy
CVE-2026-101028

6MEDIUM

Key Information:

Status
Vendor
CVE Published:
9 October 2026

What is CVE-2026-101028?

An Incorrect Authorization vulnerability exists in the Ash Project, which can allow unauthorized actors to infer sensitive data from records they do not have permission to access. This vulnerability arises primarily due to the Ash.Actions.Aggregate.run/4 method, which applies only the read policy of the root resource but not the corresponding policies of related resources. As a result, attackers can craft queries that utilize functions like Ash.count/2 or Ash.exists/2, potentially recovering sensitive information about hidden related records through aggregate queries. Users of Ash versions ranging from 2.6.0 to before 3.34.6 are encouraged to apply available patches to mitigate this risk.

Affected Version(s)

ash 2.6.0 < 3.34.6

ash 30eaf1c6e8524527b703e3c4bfeff7967ee0b37c < 80936187b27ee94f15cd875affd3141b5cb23185

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Glenn Rempe
Glenn Rempe
Zach Daniel / Ash Project
.