Ash · Ash · CVE-2026-101028
**Name of the Vulnerable Software and Affected Versions**
ash versions 2.6.0 through 3.34.5
**Description**
An incorrect authorization issue allows an actor to infer data in related records they are not permitted to read. This occurs because the function `Ash.Actions.Aggregate.run/4` only applied the root resource's read policy before executing the aggregate query, skipping the read policies of related resources. A caller can test conditions against hidden related rows to recover their existence and attribute values one query at a time if their filter or sort reaches the `Ash.count/2`, `Ash.exists/2`, or `Ash.aggregate/3` functions. This can happen through `Ash.Query.filter input/2`, an ash lua script, or an AshAi tool. This issue is reachable when an application passes caller-supplied filters or sorts that cross a relationship into the affected functions and the related resource's read policy is stricter than the root resource's.
**Recommendations**
Update ash to version 3.34.6 or later.