PT-2026-84096 · Ash · Ash

·

CVE-2026-82747

·

Published

2026-09-01

·

Updated

2026-09-01

CVSS v4.0

5.9

Medium

VectorAV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions ash versions 3.4.44 through 3.32.1
Description An incorrect authorization issue exists where records that should be denied by a runtime read policy are returned to any actor. This occurs when a resource uses an access type :runtime read policy, which is a check evaluated per record instead of being compiled into a filter. The check result/1 function in lib/ash/policy/authorizer/authorizer.ex fails to properly handle cases where all policy scenarios for a record are impossible; instead of forbidding the record, the system returns it as authorized.
Recommendations Update ash to version 3.32.2 or later.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82747
GHSA-4259-GVR2-4XHQ

Affected Products

Ash