Authorization Flaw in Ash Phoenix Affects User Access Control
CVE-2026-82724
7.6HIGH
What is CVE-2026-82724?
An incorrect authorization vulnerability in the Ash Phoenix framework allows improper tenant-scoped access checks. The flaw arises because the SubdomainHook authorization callback operates with a nil tenant, preventing it from enforcing the intended access controls. As a result, the initial access evaluation may evaluate to nil, either causing a crash or erroneously granting access. This issue occurs in versions before 2.3.25, where an update has been issued to correct the functionality by ensuring that the tenant assignment is properly handled within the access check lifecycle.
Affected Version(s)
ash_phoenix 2.1.26 < 2.3.25
ash_phoenix 9a5ea4d377bc263de321d79574872a3dfc4fb541
References
CVSS V4
Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Peter Ullrich
Peter Ullrich
Zach Daniel / Ash Project
Jonatan Männchen / EEF
