CVE-2026-101028Medium· 6.5▾ SunlitIncorrect Authorization vulnerability in ash-project ash allows an actor to infer data in related records they cannot read via Ash.count/2, Ash.exists/2 and Ash.aggregate/3. Ash.Actions.Aggregate.run/4 (lib/ash/actions/aggregate.ex) app…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
— → 6.5
none → medium
Incorrect Authorization vulnerability in ash-project ash allows an actor to infer data in related records they cannot read via Ash.count/2, Ash.exists/2 and Ash.aggregate/3.
Ash.Actions.Aggregate.run/4 (lib/ash/actions/aggregate.ex) applied only the root resource's read policy before running the aggregate query. The read path also applies each related resource's read policy to filter and sort references that cross a relationship, directly (for example comments.body) or through an aggregate over one, but the aggregate path skipped that step. A caller whose filter or sort reaches these functions, for example through Ash.Query.filter_input/2, an ash_lua script, or an AshAi tool offering count or exists results, can test conditions against related rows hidden from them and recover their existence and attribute values one query at a time. Ash.read/2 and its page counts are not affected.
This issue affects ash: from 2.6.0 before 3.34.6.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-106471High· 8.1A flaw was found in Candlepin
CVE-2026-105447Medium· 5.5A flaw was found in Quay
CVE-2026-107889Medium· 5.5A flaw was found in the login theme rendering component of Keycloak
CVE-2026-107727Low· 3.7Strawberry GraphQL is a library for creating GraphQL APIs
CVE-2026-107161High· 7.5A heap-based buffer overflow flaw was found in Cyrus SASL
CVE-2026-106061Medium· 5.5A flaw was found in GIMP’s X cursor (XMC) thumbnail loader