Incorrect Authorization in ash_sql Affects Ash Project by Ash-Project
CVE-2026-77454
What is CVE-2026-77454?
An incorrect authorization vulnerability exists in ash_sql that enables attackers to bypass authorization filters, allowing unauthorized access to sensitive data. Specifically, the 'exists/2' predicate fails to enforce proper filtering due to an erroneous handling of relationships that include both limits and parent-referencing filters. When this occurs, the built-in policy checks, like 'authorize_if', can be easily circumvented, granting access to any user with a related row without proper scoping conditions. This vulnerability affects ash_sql versions from 0.4.1 up to, but not including, 0.7.1.
Affected Version(s)
ash_sql 0.4.1 < 0.7.1
ash_sql e26a63b29bd7501505fafd726f14262cdc3b6629 < 865fdd4e5e70724a23b19c048e6768c31d2209ab
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
