Sensitive Information Exposure in Ash Project's Resource Validation
CVE-2026-82739

2.1LOW

Key Information:

Status
Vendor
CVE Published:
1 September 2026

What is CVE-2026-82739?

A vulnerability in the Ash project's resource validation system allows unauthorized actors to access sensitive data through error messages. Specifically, when a confirmation check fails, the system returns an error message containing the stored value of the confirmed field instead of the supplied confirmation. This poses a significant risk as malicious users can exploit this to retrieve sensitive information by deliberately submitting incorrect confirmation inputs. A patch has been deployed to ensure that only the actor-supplied confirmation appears in the error messages.

Affected Version(s)

ash 2.17.20 < 3.32.2

ash fadecf3ee95640bd3bc7298df4799e0375537fd2 < 7dfe5f0b1ba4267580ded947dc861351d4dc8e2b

References

CVSS V4

Score:
2.1
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jonatan Männchen / EEF
Peter Ullrich
Zach Daniel / Ash Project
Peter Ullrich
.