PT-2026-83676 · Ash Admin · Ash Admin

·

CVE-2026-75757

·

Published

2026-08-31

·

Updated

2026-08-31

CVSS v4.0

8.3

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions ash admin versions 0.9.1 through 1.3.0
Description An issue exists where the client JavaScript reads state cookies—specifically tenant, actor resource, actor primary key, actor action, actor domain, actor authorizing, and actor paused—using an unanchored regular expression against document.cookie. This allows any cookie whose name ends with the requested name to match. Consequently, an attacker controlling a sibling subdomain can set a shadowing cookie with a broader domain (e.g., .example.com) that flows unvalidated into the LiveSocket connect parameters, enabling the rebinding of an admin session to a different actor, tenant, or authorization mode.
Recommendations Update ash admin to version 1.3.1 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-75757
GHSA-3259-55FP-W94J

Affected Products

Ash Admin