Authorization Flaw in Ash_SQL Multitenant Application by Ash Project
CVE-2026-81318

2.1LOW

Key Information:

Status
Vendor
CVE Published:
30 August 2026

What is CVE-2026-81318?

An incorrect authorization vulnerability in Ash_SQL allows an attacker in a schema-based multitenant application to access aggregate values from another tenant's data. This occurs due to a flaw in the outer query construction, which fails to carry appropriate tenant schema prefixes. As a result, sensitive data intended for one tenant can be improperly accessed by another. Versions of ash_sql from 0.1.0 before 0.7.1 are affected, emphasizing the need for prompt patching to secure tenant isolation and protect sensitive information.

Affected Version(s)

ash_sql 0.1.0 < 0.7.1

ash_sql dd092ed273dec7bd2194352f24a39229fc8ae68b < 3d95478cc9e1d5bfaf6144fe9b9793f29e5ab889

References

CVSS V4

Score:
2.1
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peter Ullrich
Peter Ullrich
Zach Daniel / Ash Project
Jonatan Männchen / EEF
.