PT-2026-83548 · Ash Sql · Ash Sql

·

CVE-2026-81316

·

Published

2026-08-30

·

Updated

2026-08-30

CVSS v4.0

2.1

Low

VectorAV:L/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions ash sql versions 0.1.0 through 0.7.0
Description An incorrect authorization issue allows a caller to receive aggregate values, such as counts, sums, or lists, that should have been excluded by a more restrictive filter. This leads to data disclosure across authorization or tenancy boundaries. The problem occurs in the different queries?/2 function, which incorrectly identifies two aggregate queries as identical if they share a name and lack different sorts, even if their filters differ. Consequently, when actor or tenant context is applied, a narrowly filtered aggregate may return the value of a previously registered broad aggregate.
Recommendations Update ash sql to version 0.7.1 or later.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-81316
GHSA-V7PF-WJXC-7J5M

Affected Products

Ash Sql