Missing Authorization Vulnerability in Ash Project by Ash
CVE-2026-82746

5.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
1 September 2026

What is CVE-2026-82746?

A missing authorization vulnerability in Ash Project's Ash product enables unauthorized actors to update records that are typically restricted by resource policies. The flaw arises from the Ash.update_many/4 function, which executes an atomic update without properly enforcing the resource policies. As a result, an actor can manipulate records across various rows, including those owned by others. The vulnerability has been addressed by updating the atomic strategy to ensure that only authorized changes are executed, thereby reinforcing data integrity and compliance with established policies.

Affected Version(s)

ash 3.29.0 < 3.32.2

ash 45e6b4ec7b2dc076afe614aa7aef7e1f15b5e335

References

CVSS V4

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jonatan Männchen / EEF
Zach Daniel / Ash Project
Peter Ullrich
Peter Ullrich
.