Incorrect Authorization in Ash Project for Ash Framework by Ash Project
CVE-2026-82747
What is CVE-2026-82747?
An Incorrect Authorization vulnerability exists in the Ash Framework where a runtime read policy may erroneously allow records to be returned to any actor despite being denied by the policy. This flaw arises when the Ash.Policy.Authorizer evaluates the records, discarding impossible policy scenarios but inadvertently retaining denied records in the authorization check results. Consequently, records that should be forbidden may still be delivered as authorized, compromising the intended access restrictions. The issue affects versions of the Ash Framework prior to 3.32.2 and has been addressed with an update that correctly forbids records with all impossible scenarios.
Affected Version(s)
ash 3.4.44 < 3.32.2
ash f4a8ff53fd3b974468d73685cd3fc842ef893de3 < 6eddb8ab26e45023faf0c79ebd152bb40aefda02
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
