Unchecked Return Value Vulnerability in ash_postgres by Ash Project
CVE-2026-78699

7.2HIGH

Key Information:

Vendor
CVE Published:
30 August 2026

What is CVE-2026-78699?

An unchecked return value vulnerability in ash_postgres can enable a tenant to rename their schema to collide with another existing tenant's schema. This flaw arises during the execution of the RENAME SCHEMA command, where the return value of the operation is not properly handled. As a result, the action appears successful even when it fails, allowing unauthorized access to another tenant's data. This issue affects ash_postgres from versions 0.25.0 to 2.13.0.

Affected Version(s)

ash_postgres 0.25.0 < 2.13.0

ash_postgres 03510dae24020e302558ef947be7ea874a9ce756 < 8544ab15fe45784553c2d2da8ee1a388eee0174b

References

CVSS V4

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peter Ullrich
Peter Ullrich
Zach Daniel / Ash Project
Jonatan Männchen / EEF
.