Information Disclosure in Ash Framework Affecting Calculations and Aggregates
CVE-2026-86338

6MEDIUM

Key Information:

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-86338?

A security flaw in the Ash framework enables lower-privileged users to access sensitive data protected by field policies. The vulnerability arises from a failure to apply nilling to calculations and aggregates during filter operations. Users can exploit this oversight by referencing calculations or aggregates that they are prohibited from seeing, thereby learning protected values through filter query results. This exposure was prevalent in versions of Ash prior to 3.33.4, necessitating an urgent patch to ensure comprehensive data security. The fix ensures that all filter references are treated with the same strictness as attributes, effectively safeguarding sensitive information from unauthorized access.

Affected Version(s)

ash 2.11.0-rc.0 < 3.33.4

ash 0b6d93c7c4637280b46ae66ea1d2eaf013701238

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jesse Williams
Zach Daniel / Ash Project
Jonatan Männchen / EEF
Jesse Williams
.