Insufficient Random Value Vulnerability in Ash-Project's Ash_Admin
CVE-2026-81852

2.1LOW

Key Information:

Status
Vendor
CVE Published:
31 August 2026

What is CVE-2026-81852?

An insufficiently random values vulnerability exists in Ash-Project's Ash_Admin, where a hardcoded, publicly known Content Security Policy (CSP) nonce compromises nonce-based protections. The application defaults to a constant nonce value for inline scripts and styles, allowing attackers to exploit any HTML-injection sink on admin pages. This issue severely undermines the intended security measures, as the nonces are predictable and reused across requests. Affected versions include those from 0.10.8 up to, but not including, 1.3.1. The resolution involves generating a unique nonce for each request, thereby enhancing the security posture of the application.

Affected Version(s)

ash_admin 0.10.8 < 1.3.1

ash_admin 99b8daed7b2f79d82fcd9e89338d41b0e1564aa7

References

CVSS V4

Score:
2.1
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peter Ullrich
Peter Ullrich
Zach Daniel / Ash Project
Jonatan Männchen / EEF
.