Information Disclosure in Ash Framework Affecting Calculations and Aggregates
CVE-2026-86338
What is CVE-2026-86338?
A security flaw in the Ash framework enables lower-privileged users to access sensitive data protected by field policies. The vulnerability arises from a failure to apply nilling to calculations and aggregates during filter operations. Users can exploit this oversight by referencing calculations or aggregates that they are prohibited from seeing, thereby learning protected values through filter query results. This exposure was prevalent in versions of Ash prior to 3.33.4, necessitating an urgent patch to ensure comprehensive data security. The fix ensures that all filter references are treated with the same strictness as attributes, effectively safeguarding sensitive information from unauthorized access.
Affected Version(s)
ash 2.11.0-rc.0 < 3.33.4
ash 0b6d93c7c4637280b46ae66ea1d2eaf013701238
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
