Improper Attribute Modification in Ash-Project's Ash_Oban Plugin
CVE-2026-78038

5.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
30 August 2026

What is CVE-2026-78038?

The Ash_Oban plugin is susceptible to improper handling of user input due to a flaw in how dynamically determined attributes are managed. An attacker can exploit this vulnerability by manipulating the :args option in the AshOban.build_trigger/3 function, allowing them to redirect update or destruction actions to different records, compromising tenant isolation. This flaw arises because the merging of user inputs does not appropriately handle key collisions due to JSON processing, leading to unexpected behavior and potential authorization bypass, especially in applications that inadequately shield this option from direct user influence. Users utilizing versions from 0.2.5 up to 0.8.14 are recommended to apply the fixes provided in recent patches to safeguard their applications.

Affected Version(s)

ash_oban 0.2.5 < 0.8.14

ash_oban ce079229ecdf0d323da2b554f30fc569e54660f0

References

CVSS V4

Score:
5.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peter Ullrich
Peter Ullrich
Zach Daniel / Ash Project
Jonatan Männchen / EEF
.