Authorization Bypass in AshAdmin by Ash Project
CVE-2026-81853
What is CVE-2026-81853?
A vulnerability exists in AshAdmin that allows an attacker to exploit the authorization mechanism by utilizing a user-controlled key. This weakness enables unauthorized users to conduct equality queries against sensitive attributes by manipulating record-lookup URLs. Specifically, the functionality in AshAdmin fails to properly validate the primary keys derived from user input, allowing attackers to attempt to retrieve sensitive information such as API tokens through brute force by altering the lookup filters. The vulnerability allows any already-interned attribute name to be used, posing significant risk to the confidentiality of sensitive data. To mitigate this threat, a patch has been introduced to ensure that only valid primary-key fields are decoded and incorporated in the lookup filters.
Affected Version(s)
ash_admin 0.1.0 < 1.3.1
ash_admin 98b03baa8422b94dd13e305bf08b8ee3f7232c7b < 3c3e905d47f1155dcc1ca3fb347348b05a66065a
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
