Incorrect Authorization in Ash Project for Ash Framework by Ash Project
CVE-2026-82747

5.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
1 September 2026

What is CVE-2026-82747?

An Incorrect Authorization vulnerability exists in the Ash Framework where a runtime read policy may erroneously allow records to be returned to any actor despite being denied by the policy. This flaw arises when the Ash.Policy.Authorizer evaluates the records, discarding impossible policy scenarios but inadvertently retaining denied records in the authorization check results. Consequently, records that should be forbidden may still be delivered as authorized, compromising the intended access restrictions. The issue affects versions of the Ash Framework prior to 3.32.2 and has been addressed with an update that correctly forbids records with all impossible scenarios.

Affected Version(s)

ash 3.4.44 < 3.32.2

ash f4a8ff53fd3b974468d73685cd3fc842ef893de3 < 6eddb8ab26e45023faf0c79ebd152bb40aefda02

References

CVSS V4

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jonatan Männchen / EEF
Zach Daniel / Ash Project
Peter Ullrich
Peter Ullrich
.