Description
Incorrect Authorization vulnerability in ash-project ash allows Exploiting Incorrectly Configured Access Control Security Levels. This vulnerability is associated with program files lib/ash/actions/create/bulk.ex, lib/ash/actions/destroy/bulk.ex, lib/ash/actions/update/bulk.ex and program routines 'Elixir.Ash.Actions.Create.Bulk':run/5, 'Elixir.Ash.Actions.Destroy.Bulk':run/6, 'Elixir.Ash.Actions.Update.Bulk:run'/6.

This issue affects ash: from 0.1.0 before 3.5.39.
Published: 2025-09-07
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an incorrect authorization flaw that allows attackers to trigger bulk create, destroy, or update actions in the ash library without proper permission checks. This flaw is introduced in the bulk action modules and routines within the Ash framework, enabling an attacker to perform unauthorized modifications to resources. The weakness is identified as CWE‑863 and carries a CVSS score of 7.1, indicating moderate‑to‑high severity for confidentiality, integrity, and availability compromise.

Affected Systems

The issue affects all releases of the ash library from the initial version 0.1.0 up to, but not including, 3.5.39. The flaw resides in the files lib/ash/actions/create/bulk.ex, lib/ash/actions/destroy/bulk.ex, and lib/ash/actions/update/bulk.ex, as well as the corresponding Elixir routines. Any build or package based on those releases, particularly those hosted on Hex, is impacted.

Risk and Exploitability

The low EPSS score (<1%) indicates a small chance of public exploitation, and the vulnerability is not currently listed in the CISA KEV catalog. The description suggests that the flaw is triggered by requests to an ash‑based service, implying a likely network‑based attack vector, though this is inferred rather than explicitly documented. An attacker could exploit the missing authorization checks to perform bulk operations that bypass intended access controls.

Generated by OpenCVE AI on August 4, 2026 at 19:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the ash library to version 3.5.39 or later to incorporate the authorization fix.
  • If upgrading is not immediately possible, apply the patch from commit 5d1b6a5d00771fd468a509778637527b5218be9a, which restores proper permission checks for bulk actions.
  • After applying the fix or patch, audit the bulk‑action endpoints to confirm correct authorization enforcement and review system logs for any unintended activity.

Generated by OpenCVE AI on August 4, 2026 at 19:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-27096 Before action, Ash's hooks may execute in certain scenarios despite a request being forbidden
Github GHSA Github GHSA GHSA-jj4j-x5ww-cwh9 Before action, Ash's hooks may execute in certain scenarios despite a request being forbidden
History

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Description Incorrect Authorization vulnerability in ash-project ash allows Exploiting Incorrectly Configured Access Control Security Levels. This vulnerability is associated with program files lib/ash/actions/create/bulk.ex, lib/ash/actions/destroy/bulk.ex, lib/ash/actions/update/bulk.ex and program routines 'Elixir.Ash.Actions.Create.Bulk':run/5, 'Elixir.Ash.Actions.Destroy.Bulk':run/6, 'Elixir.Ash.Actions.Update.Bulk:run'/6. This issue affects ash: from pkg:hex/ash before pkg:hex/ash@3.5.39, before 3.5.39, before 5d1b6a5d00771fd468a509778637527b5218be9a. Incorrect Authorization vulnerability in ash-project ash allows Exploiting Incorrectly Configured Access Control Security Levels. This vulnerability is associated with program files lib/ash/actions/create/bulk.ex, lib/ash/actions/destroy/bulk.ex, lib/ash/actions/update/bulk.ex and program routines 'Elixir.Ash.Actions.Create.Bulk':run/5, 'Elixir.Ash.Actions.Destroy.Bulk':run/6, 'Elixir.Ash.Actions.Update.Bulk:run'/6. This issue affects ash: from 0.1.0 before 3.5.39.

Mon, 06 Apr 2026 16:45:00 +0000


Mon, 08 Sep 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 07 Sep 2025 16:15:00 +0000

Type Values Removed Values Added
Description Incorrect Authorization vulnerability in ash-project ash allows Exploiting Incorrectly Configured Access Control Security Levels. This vulnerability is associated with program files lib/ash/actions/create/bulk.ex, lib/ash/actions/destroy/bulk.ex, lib/ash/actions/update/bulk.ex and program routines 'Elixir.Ash.Actions.Create.Bulk':run/5, 'Elixir.Ash.Actions.Destroy.Bulk':run/6, 'Elixir.Ash.Actions.Update.Bulk:run'/6. This issue affects ash: from pkg:hex/ash before pkg:hex/ash@3.5.39, before 3.5.39, before 5d1b6a5d00771fd468a509778637527b5218be9a.
Title Before action hooks may execute in certain scenarios despite a request being forbidden
First Time appeared Ash-project
Ash-project ash
Weaknesses CWE-863
CPEs cpe:2.3:a:ash-project:ash:*:*:*:*:*:*:*:*
Vendors & Products Ash-project
Ash-project ash
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: EEF

Published:

Updated: 2026-07-24T14:14:03.285Z

Reserved: 2025-05-15T08:40:25.455Z

Link: CVE-2025-48042

cve-icon Vulnrichment

Updated: 2025-09-08T18:55:06.932Z

cve-icon NVD

Status : Deferred

Published: 2025-09-07T16:15:51.240

Modified: 2026-07-24T15:17:06.920

Link: CVE-2025-48042

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T19:15:03Z

Weaknesses