Authorization Flaw in Ash Project Affects User Data Privacy
CVE-2026-101028
What is CVE-2026-101028?
An Incorrect Authorization vulnerability exists in the Ash Project, which can allow unauthorized actors to infer sensitive data from records they do not have permission to access. This vulnerability arises primarily due to the Ash.Actions.Aggregate.run/4 method, which applies only the read policy of the root resource but not the corresponding policies of related resources. As a result, attackers can craft queries that utilize functions like Ash.count/2 or Ash.exists/2, potentially recovering sensitive information about hidden related records through aggregate queries. Users of Ash versions ranging from 2.6.0 to before 3.34.6 are encouraged to apply available patches to mitigate this risk.
Affected Version(s)
ash 2.6.0 < 3.34.6
ash 30eaf1c6e8524527b703e3c4bfeff7967ee0b37c < 80936187b27ee94f15cd875affd3141b5cb23185
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
