Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Glenn Rempe

#47981of 57,652
6Total CVSS
Vulnerabilities · 1
PT-2026-108749
6.0
2026-10-09
Ash · Ash · CVE-2026-101028
**Name of the Vulnerable Software and Affected Versions** ash versions 2.6.0 through 3.34.5 **Description** An incorrect authorization issue allows an actor to infer data in related records they are not permitted to read. This occurs because the function `Ash.Actions.Aggregate.run/4` only applied the root resource's read policy before executing the aggregate query, skipping the read policies of related resources. A caller can test conditions against hidden related rows to recover their existence and attribute values one query at a time if their filter or sort reaches the `Ash.count/2`, `Ash.exists/2`, or `Ash.aggregate/3` functions. This can happen through `Ash.Query.filter input/2`, an ash lua script, or an AshAi tool. This issue is reachable when an application passes caller-supplied filters or sorts that cross a relationship into the affected functions and the related resource's read policy is stricter than the root resource's. **Recommendations** Update ash to version 3.34.6 or later.