Improper Control of Object Attributes in Ash Project by Ash Vendor
CVE-2026-93477

5.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
25 September 2026

What is CVE-2026-93477?

The vulnerability arises from the inadequate handling of private action arguments in bulk destroy and bulk update operations of the Ash Project. Attackers can exploit this flaw to manipulate private arguments that should only be set by trusted server-side code. This could potentially lead to serious security issues, including integrity violations and privilege escalations, as unauthorized users might gain control over critical application components. The recommended fix necessitates strict checks on public attributes in matching parameters, ensuring that private arguments remain secure and can only be modified server-side.

Affected Version(s)

ash 2.17.15 < 3.33.11

ash 8c17434803b2e91de522bdfbd0ca918e5d5898df < 6b7ac53a0a2532291eb940d7beaf0fbb2da6fc4f

References

CVSS V4

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

zx
zx
Zach Daniel / Ash Project
Jonatan Männchen / EEF
.