Missing Authorization Vulnerability in Ash Project by Ash
CVE-2026-82746
5.9MEDIUM
What is CVE-2026-82746?
A missing authorization vulnerability in Ash Project's Ash product enables unauthorized actors to update records that are typically restricted by resource policies. The flaw arises from the Ash.update_many/4 function, which executes an atomic update without properly enforcing the resource policies. As a result, an actor can manipulate records across various rows, including those owned by others. The vulnerability has been addressed by updating the atomic strategy to ensure that only authorized changes are executed, thereby reinforcing data integrity and compliance with established policies.
Affected Version(s)
ash 3.29.0 < 3.32.2
ash 45e6b4ec7b2dc076afe614aa7aef7e1f15b5e335
References
CVSS V4
Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Jonatan Männchen / EEF
Zach Daniel / Ash Project
Peter Ullrich
Peter Ullrich
