Failing Open Vulnerability in ash-project's Ash Framework
CVE-2026-82744

2.1LOW

Key Information:

Status
Vendor
CVE Published:
1 September 2026

What is CVE-2026-82744?

A failing open vulnerability in the Ash Framework allows security-relevant changes to be bypassed when validations raise exceptions on attacker-influenced input. This occurs because the Ash.Reactor.ChangeStep improperly treats raised exceptions, enabling attackers to exploit this flaw and undermine expected security protocols. As a result, modifications intended to enforce security measures may not be executed, allowing possible breaches. Developers are advised to update to versions 3.32.2 and above to mitigate this issue.

Affected Version(s)

ash 3.0.0-rc.17 < 3.32.2

ash 321f43bd05ad9544e693cbf797243693e51a6be4 < 6d2eb86ea8d2ba5ffac89c1b8b9bf46e331feabc

References

CVSS V4

Score:
2.1
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peter Ullrich
Jonatan Männchen / EEF
Zach Daniel / Ash Project
Peter Ullrich
.