Incorrect Authorization in ash_sql Affects Ash Project by Ash-Project
CVE-2026-77454

5.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
30 August 2026

What is CVE-2026-77454?

An incorrect authorization vulnerability exists in ash_sql that enables attackers to bypass authorization filters, allowing unauthorized access to sensitive data. Specifically, the 'exists/2' predicate fails to enforce proper filtering due to an erroneous handling of relationships that include both limits and parent-referencing filters. When this occurs, the built-in policy checks, like 'authorize_if', can be easily circumvented, granting access to any user with a related row without proper scoping conditions. This vulnerability affects ash_sql versions from 0.4.1 up to, but not including, 0.7.1.

Affected Version(s)

ash_sql 0.4.1 < 0.7.1

ash_sql e26a63b29bd7501505fafd726f14262cdc3b6629 < 865fdd4e5e70724a23b19c048e6768c31d2209ab

References

CVSS V4

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peter Ullrich
Peter Ullrich
Zach Daniel / Ash Project
Jonatan Männchen / EEF
.