Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Jesse Williams

#47899of 57,604
6Total CVSS
Vulnerabilities · 1
PT-2026-93377
6.0
2026-09-16
Ash · Ash · CVE-2026-86338
**Name of the Vulnerable Software and Affected Versions** ash versions 2.11.0-rc.0 through 3.33.3 **Description** Field policies are intended to prevent information disclosure by replacing fields an actor cannot see with a `nil` expression when used in a filter, preventing the filter from acting as a yes/no oracle. However, this mechanism was only applied to attributes and not to calculations or aggregates. Because user-supplied filter references to calculations or aggregates use `Ash.Query.Calculation` or `Ash.Query.Aggregate` structs, they bypassed the authorizer's reference replacement which only matched `Ash.Resource.*` structs. Consequently, an actor forbidden from accessing a calculation or aggregate can still filter by it, allowing them to deduce protected values based on whether rows match. This is particularly risky when filtering is exposed to lower-privileged actors via AshGraphql or AshJsonApi filter arguments. **Recommendations** Update ash to version 3.33.4 or later.