PT-2026-98374 · Ash · Ash

CVE-2026-93477

·

Published

2026-09-25

·

Updated

2026-09-25

CVSS v4.0

5.9

Medium

VectorAV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions ash versions 2.17.15 through 3.33.10
Description An Improperly Controlled Modification of Dynamically-Determined Object Attributes allows users to set values for private action arguments during bulk destroy and bulk update operations. Arguments marked with public?: false are intended to be restricted to trusted server-side code and should not be modifiable via end-user input. The functions Ash.Actions.Destroy.Bulk.base changeset/5 and Ash.Actions.Update.Bulk.base changeset/5 fail to verify the public? attribute when matching keys from user-supplied parameter maps. Consequently, an attacker providing parameters to bulk destroy or bulk update actions—via AshJsonApi, AshGraphql, or controllers forwarding to Ash.bulk destroy/4 or Ash.bulk update/4—can manipulate private arguments. If these arguments, such as acting user id, are used for authorization, record ownership, or audit metadata, this can result in privilege escalation or integrity violations.
Recommendations Update ash to version 3.33.11 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-93477
GHSA-C2P4-P7Q6-HR2J

Affected Products

Ash