Authorization Flaw in Ash_SQL Multitenant Application by Ash Project
CVE-2026-81318
2.1LOW
What is CVE-2026-81318?
An incorrect authorization vulnerability in Ash_SQL allows an attacker in a schema-based multitenant application to access aggregate values from another tenant's data. This occurs due to a flaw in the outer query construction, which fails to carry appropriate tenant schema prefixes. As a result, sensitive data intended for one tenant can be improperly accessed by another. Versions of ash_sql from 0.1.0 before 0.7.1 are affected, emphasizing the need for prompt patching to secure tenant isolation and protect sensitive information.
Affected Version(s)
ash_sql 0.1.0 < 0.7.1
ash_sql dd092ed273dec7bd2194352f24a39229fc8ae68b < 3d95478cc9e1d5bfaf6144fe9b9793f29e5ab889
References
CVSS V4
Score:
2.1
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Peter Ullrich
Peter Ullrich
Zach Daniel / Ash Project
Jonatan Männchen / EEF
