Authorization Flaw in Ash Phoenix Affects User Access Control
CVE-2026-82724

7.6HIGH

Key Information:

Vendor
CVE Published:
31 August 2026

What is CVE-2026-82724?

An incorrect authorization vulnerability in the Ash Phoenix framework allows improper tenant-scoped access checks. The flaw arises because the SubdomainHook authorization callback operates with a nil tenant, preventing it from enforcing the intended access controls. As a result, the initial access evaluation may evaluate to nil, either causing a crash or erroneously granting access. This issue occurs in versions before 2.3.25, where an update has been issued to correct the functionality by ensuring that the tenant assignment is properly handled within the access check lifecycle.

Affected Version(s)

ash_phoenix 2.1.26 < 2.3.25

ash_phoenix 9a5ea4d377bc263de321d79574872a3dfc4fb541

References

CVSS V4

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peter Ullrich
Peter Ullrich
Zach Daniel / Ash Project
Jonatan Männchen / EEF
.