Authorization Bypass in AshAdmin by Ash Project
CVE-2026-81853

2.3LOW

Key Information:

Status
Vendor
CVE Published:
31 August 2026

What is CVE-2026-81853?

A vulnerability exists in AshAdmin that allows an attacker to exploit the authorization mechanism by utilizing a user-controlled key. This weakness enables unauthorized users to conduct equality queries against sensitive attributes by manipulating record-lookup URLs. Specifically, the functionality in AshAdmin fails to properly validate the primary keys derived from user input, allowing attackers to attempt to retrieve sensitive information such as API tokens through brute force by altering the lookup filters. The vulnerability allows any already-interned attribute name to be used, posing significant risk to the confidentiality of sensitive data. To mitigate this threat, a patch has been introduced to ensure that only valid primary-key fields are decoded and incorporated in the lookup filters.

Affected Version(s)

ash_admin 0.1.0 < 1.3.1

ash_admin 98b03baa8422b94dd13e305bf08b8ee3f7232c7b < 3c3e905d47f1155dcc1ca3fb347348b05a66065a

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peter Ullrich
Peter Ullrich
Zach Daniel / Ash Project
Jonatan Männchen / EEF
.