Authorization Bypass Vulnerability in Ash Phoenix by Ash Project
CVE-2026-82725

2.3LOW

Key Information:

Vendor
CVE Published:
31 August 2026

What is CVE-2026-82725?

The Ash Phoenix product from the Ash Project contains a vulnerability that allows an attacker to bypass authorization controls through user-controlled filter form parameters. This flaw enables an attacker to access relationships that the resource author has marked as non-public, effectively turning the affected queries into a boolean oracle that can expose private related data. The vulnerability arises from the way Ash Phoenix resolves user-supplied paths and fields, failing to enforce proper visibility checks on non-terminal relationships. The impact of this security issue underscores the importance of rigorous input validation and access control mechanisms in modern web applications.

Affected Version(s)

ash_phoenix 0.6.0-rc.1 < 2.3.25

ash_phoenix 06875682999938f607c970e71b6a80af90e18b3d

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peter Ullrich
Peter Ullrich
Zach Daniel / Ash Project
Jonatan Männchen / EEF
.