{"id":"CVE-2026-81643","title":"Incorrect Authorization vulnerability in ash-project ash_graphql delivers GraphQL subscription payloads for records a subscriber is not authorized to see.\n\nIn AshGraphql.Subscription.Batcher, do_send/5 resolves the first notification of …","summary":"Incorrect Authorization vulnerability in ash-project ash_graphql delivers GraphQL subscription payloads for records a subscriber is not authorized to see.\n\nIn AshGraphql.Subscription.Batcher, do_send/5 resolves the first notification of …","severity":"none","cwe":["CWE-863"],"published":"2026-08-30","updated":"2026-08-30","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-81643","references":[{"url":"https://cna.erlef.org/cves/CVE-2026-81643.html","label":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db"},{"url":"https://github.com/ash-project/ash_graphql/commit/e8e67f39add2ce0771e6db5f086afe68ba212c57","label":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db"},{"url":"https://github.com/ash-project/ash_graphql/security/advisories/GHSA-j684-hch4-q888","label":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db"},{"url":"https://osv.dev/vulnerability/EEF-CVE-2026-81643","label":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db"}],"tags":["nvd"],"ingestedAt":"2026-08-31T02:00:58.405Z","epss":0.00246,"epssPercentile":0.16161,"slug":"CVE-2026-81643","body":"## Overview\n\nIncorrect Authorization vulnerability in ash-project ash_graphql delivers GraphQL subscription payloads for records a subscriber is not authorized to see.\n\nIn AshGraphql.Subscription.Batcher, do_send/5 resolves the first notification of a batch and filters it with should_send?/1, which drops results whose errors are coded forbidden or not_found or carry no code, precisely so that unauthorized results are not disclosed. The remaining notifications in the batch are read from the process dictionary, re-run through the pipeline, and appended to the outgoing results without that filter. They reach pubsub.publish_subscription/2, and the not is_nil(record) guard drops only nil records, not error-carrying results. Any two qualifying notifications arriving within the default one-second batch interval suffice, and batching is the default path. The fix applies should_send?/1 to the whole batch.\n\nThis issue affects ash_graphql: from 1.4.0 before 1.11.0.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}