CVE-2026-78216
Deferred Deferred - Pending Action

Information Disclosure via Aggregate Field Access in AshLua

Vulnerability report for CVE-2026-78216, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-08

Assigner: EEF

Description

AshLua exposes Ash read actions to Lua scripts run through an eval action. A read call accepts an operation (list, min, max, first, sum, avg) that builds an ad-hoc Ash.Query.Aggregate over a named field and returns its raw value. Ash field policies redact forbidden fields on returned records (replacing them with %Ash.ForbiddenField{}), but that redaction does not apply to aggregate values. A script could therefore read a field the calling actor's field policies forbid by requesting it as an aggregate instead of as a field. This includes fields that are public? true but restricted per-actor by a field policy, such as sensitive PII. The prior hardening only enforced the exposed-field allow-list (field visibility), which is a separate axis from per-actor field-policy authorization. The fix authorizes the aggregated field against the resource's field policies, so aggregating over a field the actor may not see is refused or scoped to the rows where it is visible. This issue affects ash_lua: from 0.1.0 before 0.2.2.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-08
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ash_lua ash_lua From 0.1.0 (inc) to 0.2.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1220 The product implements access controls via a policy or other feature with the intention to disable or restrict accesses (reads and/or writes) to assets in a system from untrusted agents. However, implemented access controls lack required granularity, which renders the control policy too broad because it allows accesses from unauthorized agents to the security-sensitive assets.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

AshLua allows Lua scripts to execute read actions that build aggregate queries over fields. Field policies that redact sensitive data do not apply to these aggregate values, letting scripts bypass restrictions by requesting forbidden fields as aggregates instead of direct fields. This exposes sensitive PII or restricted data to unauthorized actors.

Impact Analysis

An attacker could exploit this to read sensitive data they are not authorized to access by using aggregate operations. This bypasses field-level security controls, potentially leaking confidential information like PII or other restricted fields.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive personal data, violating GDPR's data protection principles and HIPAA's privacy rules. It undermines access controls required for compliance by allowing bypass of field-level restrictions.

Mitigation Strategies

Upgrade ash_lua to version 0.2.2 or later to address the vulnerability. The fix ensures field policies are enforced during aggregate operations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-78216. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart