Ash · Ash · CVE-2026-86338
**Name of the Vulnerable Software and Affected Versions**
ash versions 2.11.0-rc.0 through 3.33.3
**Description**
Field policies are intended to prevent information disclosure by replacing fields an actor cannot see with a `nil` expression when used in a filter, preventing the filter from acting as a yes/no oracle. However, this mechanism was only applied to attributes and not to calculations or aggregates. Because user-supplied filter references to calculations or aggregates use `Ash.Query.Calculation` or `Ash.Query.Aggregate` structs, they bypassed the authorizer's reference replacement which only matched `Ash.Resource.*` structs.
Consequently, an actor forbidden from accessing a calculation or aggregate can still filter by it, allowing them to deduce protected values based on whether rows match. This is particularly risky when filtering is exposed to lower-privileged actors via AshGraphql or AshJsonApi filter arguments.
**Recommendations**
Update ash to version 3.33.4 or later.