PT-2026-93377 · Ash · Ash

·

CVE-2026-86338

·

Published

2026-09-16

·

Updated

2026-09-16

CVSS v4.0

6.0

Medium

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions ash versions 2.11.0-rc.0 through 3.33.3
Description Field policies are intended to prevent information disclosure by replacing fields an actor cannot see with a nil expression when used in a filter, preventing the filter from acting as a yes/no oracle. However, this mechanism was only applied to attributes and not to calculations or aggregates. Because user-supplied filter references to calculations or aggregates use Ash.Query.Calculation or Ash.Query.Aggregate structs, they bypassed the authorizer's reference replacement which only matched Ash.Resource.* structs.
Consequently, an actor forbidden from accessing a calculation or aggregate can still filter by it, allowing them to deduce protected values based on whether rows match. This is particularly risky when filtering is exposed to lower-privileged actors via AshGraphql or AshJsonApi filter arguments.
Recommendations Update ash to version 3.33.4 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-86338
GHSA-7QR8-WRVQ-566Q

Affected Products

Ash