Description
Incorrect Authorization vulnerability in ash-project ash allows Exploiting Incorrectly Configured Access Control Security Levels.

This issue affects ash: from 0.1.1 before 3.5.39.
Published: 2025-09-07
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Authorization Bypass
Action: Apply Patch
AI Analysis

Impact

The flaw in the Ash library is an incorrect authorization vulnerability that allows an attacker to bypass access control checks and gain unauthorized capabilities. This weakness, classified under CWE‑863, can lead to unauthorized manipulation of resources, affecting the confidentiality, integrity, and availability of the system the library supports.

Affected Systems

The issue applies to all releases of the ash library from version 0.1.1 up through 3.5.39, as indicated in the vulnerability data. Affected builds include any software packaging or deploying the Ash library in that version range.

Risk and Exploitability

The vulnerability carries a CVSS score of 7.1, representing moderate‑to‑high severity. Because the EPSS score is listed as less than 1 %, the likelihood of public exploitation is low. It is not currently tracked in the CISA KEV catalog. The description implies that the flaw is triggered by requests to an Ash‑based service, suggesting the attack would be executed over the network; however, this inference is drawn from the context rather than an explicit statement in the data.

Generated by OpenCVE AI on September 22, 2026 at 11:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Ash library to version 3.5.39 or later to apply the authorization fix.
  • If an upgrade is not immediately possible, apply the patch provided in commit 5d1b6a5d00771fd468a509778637527b5218be9a, which restores proper permission checks.
  • Monitor logs for any unexpected activity.

Generated by OpenCVE AI on September 22, 2026 at 11:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-27096 Before action, Ash's hooks may execute in certain scenarios despite a request being forbidden
Github GHSA Github GHSA GHSA-jj4j-x5ww-cwh9 Before action, Ash's hooks may execute in certain scenarios despite a request being forbidden
History

Tue, 22 Sep 2026 09:45:00 +0000

Type Values Removed Values Added
Description Incorrect Authorization vulnerability in ash-project ash allows Exploiting Incorrectly Configured Access Control Security Levels. This vulnerability is associated with program files lib/ash/actions/create/bulk.ex, lib/ash/actions/destroy/bulk.ex, lib/ash/actions/update/bulk.ex and program routines 'Elixir.Ash.Actions.Create.Bulk':run/5, 'Elixir.Ash.Actions.Destroy.Bulk':run/6, 'Elixir.Ash.Actions.Update.Bulk:run'/6. This issue affects ash: from 0.1.0 before 3.5.39. Incorrect Authorization vulnerability in ash-project ash allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ash: from 0.1.1 before 3.5.39.
References

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Description Incorrect Authorization vulnerability in ash-project ash allows Exploiting Incorrectly Configured Access Control Security Levels. This vulnerability is associated with program files lib/ash/actions/create/bulk.ex, lib/ash/actions/destroy/bulk.ex, lib/ash/actions/update/bulk.ex and program routines 'Elixir.Ash.Actions.Create.Bulk':run/5, 'Elixir.Ash.Actions.Destroy.Bulk':run/6, 'Elixir.Ash.Actions.Update.Bulk:run'/6. This issue affects ash: from pkg:hex/ash before pkg:hex/ash@3.5.39, before 3.5.39, before 5d1b6a5d00771fd468a509778637527b5218be9a. Incorrect Authorization vulnerability in ash-project ash allows Exploiting Incorrectly Configured Access Control Security Levels. This vulnerability is associated with program files lib/ash/actions/create/bulk.ex, lib/ash/actions/destroy/bulk.ex, lib/ash/actions/update/bulk.ex and program routines 'Elixir.Ash.Actions.Create.Bulk':run/5, 'Elixir.Ash.Actions.Destroy.Bulk':run/6, 'Elixir.Ash.Actions.Update.Bulk:run'/6. This issue affects ash: from 0.1.0 before 3.5.39.

Mon, 06 Apr 2026 16:45:00 +0000


Mon, 08 Sep 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 07 Sep 2025 16:15:00 +0000

Type Values Removed Values Added
Description Incorrect Authorization vulnerability in ash-project ash allows Exploiting Incorrectly Configured Access Control Security Levels. This vulnerability is associated with program files lib/ash/actions/create/bulk.ex, lib/ash/actions/destroy/bulk.ex, lib/ash/actions/update/bulk.ex and program routines 'Elixir.Ash.Actions.Create.Bulk':run/5, 'Elixir.Ash.Actions.Destroy.Bulk':run/6, 'Elixir.Ash.Actions.Update.Bulk:run'/6. This issue affects ash: from pkg:hex/ash before pkg:hex/ash@3.5.39, before 3.5.39, before 5d1b6a5d00771fd468a509778637527b5218be9a.
Title Before action hooks may execute in certain scenarios despite a request being forbidden
First Time appeared Ash-project
Ash-project ash
Weaknesses CWE-863
CPEs cpe:2.3:a:ash-project:ash:*:*:*:*:*:*:*:*
Vendors & Products Ash-project
Ash-project ash
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: EEF

Published:

Updated: 2026-09-22T09:31:50.903Z

Reserved: 2025-05-15T08:40:25.455Z

Link: CVE-2025-48042

cve-icon Vulnrichment

Updated: 2025-09-08T18:55:06.932Z

cve-icon NVD

Status : Deferred

Published: 2025-09-07T16:15:51.240

Modified: 2026-09-22T10:17:06.810

Link: CVE-2025-48042

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T11:30:09Z

Weaknesses