PT-2026-84088 · Ash · Ash

·

CVE-2026-82739

·

Published

2026-09-01

·

Updated

2026-09-01

CVSS v4.0

2.1

Low

VectorAV:L/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions ash versions 2.17.20 through 3.32.1
Description The software discloses the stored value of a confirmed field to an actor who fails a confirmation check. This occurs because the atomic implementation of Ash.Resource.Validation.Confirm in the atomic/2 function (located in lib/ash/resource/validation/confirm.ex) constructs a mismatch error using the field being confirmed. If an actor provides only the confirmation argument and not the field itself, the atomic ref/2 function resolves the value to the current stored value, which is then echoed back in the error message. An actor can exploit this by submitting an intentionally incorrect confirmation to read the actual stored value of a sensitive attribute.
Recommendations Update ash to version 3.32.2 or later.

Exploit

Fix

Generation of Error Message Containing Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82739
GHSA-66CG-VJ5M-8W7V

Affected Products

Ash