CVE-2026-101028
Received Received - Intake

Incorrect Authorization in Ash Framework

Vulnerability report for CVE-2026-101028, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: EEF

Description

Incorrect Authorization vulnerability in ash-project ash allows an actor to infer data in related records they cannot read via Ash.count/2, Ash.exists/2 and Ash.aggregate/3. Ash.Actions.Aggregate.run/4 (lib/ash/actions/aggregate.ex) applied only the root resource's read policy before running the aggregate query. The read path also applies each related resource's read policy to filter and sort references that cross a relationship, directly (for example comments.body) or through an aggregate over one, but the aggregate path skipped that step. A caller whose filter or sort reaches these functions, for example through Ash.Query.filter_input/2, an ash_lua script, or an AshAi tool offering count or exists results, can test conditions against related rows hidden from them and recover their existence and attribute values one query at a time. Ash.read/2 and its page counts are not affected. This issue affects ash: from 2.6.0 before 3.34.6.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
ash-project ash 2.6.0
ash-project ash 30eaf1c6e8524527b703e3c4bfeff7967ee0b37c

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an Incorrect Authorization vulnerability in the ash-project ash framework. It allows an attacker to infer data in related records they cannot read by exploiting Ash.count/2, Ash.exists/2, and Ash.aggregate/3 functions. These functions skip applying related resources' read policies when filtering or sorting, enabling attackers to test conditions against hidden related rows and recover their existence and attribute values through repeated queries.

Detection Guidance

To detect this vulnerability, check if your Ash framework version is between 2.6.0 and 3.34.6. Run commands like 'mix deps.show ash' in Elixir projects to verify the installed version. Look for applications using Ash.count/2, Ash.exists/2, or Ash.aggregate/3 with filters or sorts crossing relationships.

Impact Analysis

An attacker could use this vulnerability to infer the existence or attributes of restricted related rows by querying affected functions. This could lead to confidentiality breaches where unauthorized users confirm hidden data through yes/no queries. Ash.read/2 and its page counts are not affected.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating confidentiality requirements in GDPR and HIPAA. It may result in non-compliance due to improper authorization checks allowing data exposure through aggregate queries.

Mitigation Strategies

Upgrade the Ash framework to version 3.34.6 or later. Apply the patch from commit 8093618 or update via package managers. Review applications using Ash.count/2, Ash.exists/2, or Ash.aggregate/3 to ensure filters and sorts do not bypass authorization policies.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101028. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart