PT-2026-84093 · Ash · Ash

·

CVE-2026-82744

·

Published

2026-09-01

·

Updated

2026-09-01

CVSS v4.0

2.1

Low

VectorAV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions ash versions 3.0.0-rc.17 through 3.32.1
Description The software fails to handle exceptions securely during the execution of an Ash.Reactor change step. When a guard controlling a change is evaluated in the apply where clauses/3 function within Ash.Reactor.ChangeStep, any raised exception is rescued and treated as a condition that was not met. This causes the system to bypass the change entirely instead of halting the process. Consequently, if an attacker provides specific input that triggers an exception in the guard, security-relevant modifications intended to be enforced by that change are skipped, leading to a failing open scenario.
Recommendations Update ash to version 3.32.2 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82744
GHSA-3XQ4-M876-FR88

Affected Products

Ash