Description
Incorrect Authorization vulnerability in ash-project ash allows Authentication Bypass. This vulnerability is associated with program files lib/ash/policy/policy.ex and program routines 'Elixir.Ash.Policy.Policy':expression/2.

This issue affects ash: from 3.6.3 before 3.7.1.
Published: 2025-10-17
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A mis‑evaluation of policy conditions in the Ash framework causes the system to treat a request as authenticated when the bypass condition evaluates to true, granting access to protected resources without legitimate credentials. This unauthorized access can lead to privilege escalation and compromise of both confidentiality and integrity. The weakness is classified as CWE‑863, reflecting incorrect or incomplete authorization checks.

Affected Systems

The vulnerability applies to the Ash framework produced by the ash-project. Versions 3.6.3 through 3.7.0, inclusive, are affected. Earlier releases before 3.6.3 are not impacted. Deployments running any of these affected versions should be considered vulnerable until an update is applied.

Risk and Exploitability

With a CVSS score of 8.6 the vulnerability carries a high impact, yet the EPSS score of < 1 % suggests a low current chance of exploitation. The issue is not listed in CISA’s KEV catalog. Based on the description, the attack vector is inferred to be an application‑level trigger that evaluates the policy expression; an attacker who can influence that evaluation—through crafted input or configuration—can bypass authentication without user interaction, making the flaw valuable for attackers.

Generated by OpenCVE AI on August 5, 2026 at 03:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Ash framework to version 3.7.1 or newer to apply the vendor patch.
  • Review and remove any custom policy expressions that enable bypass conditions, ensuring that policy evaluations enforce proper authentication.
  • Validate that authentication and authorization controls function correctly after the upgrade by performing targeted access‑control tests.

Generated by OpenCVE AI on August 5, 2026 at 03:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-pcxq-fjp3-r752 Ash has authorization bypass when bypass policy condition evaluates to true
History

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Description Incorrect Authorization vulnerability in ash-project ash allows Authentication Bypass. This vulnerability is associated with program files lib/ash/policy/policy.ex and program routines 'Elixir.Ash.Policy.Policy':expression/2. This issue affects ash: from pkg:hex/ash@3.6.3 before pkg:hex/ash@3.7.1, from 3.6.3 before 3.7.1, from 79749c2685ea031ebb2de8cf60cc5edced6a8dd0 before 8b83efa225f657bfc3656ad8ee8485f9b2de923d. Incorrect Authorization vulnerability in ash-project ash allows Authentication Bypass. This vulnerability is associated with program files lib/ash/policy/policy.ex and program routines 'Elixir.Ash.Policy.Policy':expression/2. This issue affects ash: from 3.6.3 before 3.7.1.

Mon, 06 Apr 2026 16:45:00 +0000


Mon, 20 Oct 2025 20:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 17 Oct 2025 14:00:00 +0000

Type Values Removed Values Added
Description Incorrect Authorization vulnerability in ash-project ash allows Authentication Bypass. This vulnerability is associated with program files lib/ash/policy/policy.ex and program routines 'Elixir.Ash.Policy.Policy':expression/2. This issue affects ash: from pkg:hex/ash@3.6.3 before pkg:hex/ash@3.7.1, from 3.6.3 before 3.7.1, from 79749c2685ea031ebb2de8cf60cc5edced6a8dd0 before 8b83efa225f657bfc3656ad8ee8485f9b2de923d.
Title Authorization bypass when bypass policy condition evaluates to true
First Time appeared Ash-project
Ash-project ash
Weaknesses CWE-863
CPEs cpe:2.3:a:ash-project:ash:*:*:*:*:*:*:*:*
Vendors & Products Ash-project
Ash-project ash
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: EEF

Published:

Updated: 2026-07-24T14:13:58.335Z

Reserved: 2025-05-15T08:40:25.455Z

Link: CVE-2025-48044

cve-icon Vulnrichment

Updated: 2025-10-20T18:42:41.664Z

cve-icon NVD

Status : Deferred

Published: 2025-10-17T14:15:46.403

Modified: 2026-07-24T15:17:07.220

Link: CVE-2025-48044

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T03:30:06Z

Weaknesses