PT-2026-108749 · Ash · Ash

·

CVE-2026-101028

·

Published

2026-10-09

·

Updated

2026-10-09

CVSS v4.0

6.0

Medium

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions ash versions 2.6.0 through 3.34.5
Description An incorrect authorization issue allows an actor to infer data in related records they are not permitted to read. This occurs because the function Ash.Actions.Aggregate.run/4 only applied the root resource's read policy before executing the aggregate query, skipping the read policies of related resources. A caller can test conditions against hidden related rows to recover their existence and attribute values one query at a time if their filter or sort reaches the Ash.count/2, Ash.exists/2, or Ash.aggregate/3 functions. This can happen through Ash.Query.filter input/2, an ash lua script, or an AshAi tool. This issue is reachable when an application passes caller-supplied filters or sorts that cross a relationship into the affected functions and the related resource's read policy is stricter than the root resource's.
Recommendations Update ash to version 3.34.6 or later.

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-101028
GHSA-XJ24-8F5C-PP5P

Affected Products

Ash