Authorization Bypass Vulnerability in Ash Project's Ash AI
CVE-2026-82564

7.1HIGH

Key Information:

Status
Vendor
CVE Published:
31 August 2026

What is CVE-2026-82564?

The vulnerability in Ash Project's Ash AI allows unauthorized users to perform update or destroy operations on database records. This occurs due to the faulty construction of update/destroy filters directly from user-provided arguments, making it possible for attackers to manipulate the records without proper identification. An attacker could exploit this by sending crafted requests that omit necessary identity keys, resulting in arbitrary records being targeted. The issue has been addressed in versions following 1.0.0, which enforce stricter validation on identity values to mitigate this risk.

Affected Version(s)

ash_ai 0.6.0 < 1.0.0

ash_ai bc2122f78fca6c11d8ec2b9ac53148ec17476460 < 87f616d5bfbf7af43346f0701ae17f853789a602

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peter Ullrich
Peter Ullrich
Jonatan Männchen / EEF / EEF
Zach Daniel / Ash Project
Jonatan Männchen / EEF
.