Description
Incorrect Authorization vulnerability in ash-project ash allows Authentication Bypass.

This issue affects ash: from 3.6.3 before 3.7.1.
Published: 2025-10-17
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Authentication Bypass
Action: Immediate Patch
AI Analysis

Impact

The Ash framework contains incorrect authorization logic that permits authentication bypass. An attacker can exploit this flaw to gain unintended access to protected resources, potentially escalating privileges and compromising confidentiality and integrity. The issue is identified as CWE‑863, indicating improper authorization checks.

Affected Systems

The vulnerability applies to the Ash framework produced by the ash-project. Versions 3.6.3 through 3.7.0, inclusive, are affected. Earlier releases before 3.6.3 are not impacted. Deployments running any of these affected versions should be considered vulnerable until an update is applied.

Risk and Exploitability

With a CVSS score of 8.6 the vulnerability carries a high impact, yet the EPSS score of < 1 % suggests a low current chance of exploitation. The issue is not listed in CISA’s KEV catalog. Based on the description, the attack vector is inferred to be an application‑level trigger that evaluates the policy expression; an attacker who can influence that evaluation—through crafted input or configuration—can bypass authentication without user interaction, making the flaw valuable for attackers.

Generated by OpenCVE AI on September 22, 2026 at 10:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Ash framework to version 3.7.1 or newer to apply the vendor patch.
  • Review and remove any custom policy expressions that enable bypass conditions, ensuring that policy evaluations enforce proper authentication.
  • Validate that authentication and authorization controls function correctly after the upgrade by performing targeted access‑control tests.

Generated by OpenCVE AI on September 22, 2026 at 10:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-pcxq-fjp3-r752 Ash has authorization bypass when bypass policy condition evaluates to true
History

Tue, 22 Sep 2026 09:45:00 +0000

Type Values Removed Values Added
Description Incorrect Authorization vulnerability in ash-project ash allows Authentication Bypass. This vulnerability is associated with program files lib/ash/policy/policy.ex and program routines 'Elixir.Ash.Policy.Policy':expression/2. This issue affects ash: from 3.6.3 before 3.7.1. Incorrect Authorization vulnerability in ash-project ash allows Authentication Bypass. This issue affects ash: from 3.6.3 before 3.7.1.
References

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Description Incorrect Authorization vulnerability in ash-project ash allows Authentication Bypass. This vulnerability is associated with program files lib/ash/policy/policy.ex and program routines 'Elixir.Ash.Policy.Policy':expression/2. This issue affects ash: from pkg:hex/ash@3.6.3 before pkg:hex/ash@3.7.1, from 3.6.3 before 3.7.1, from 79749c2685ea031ebb2de8cf60cc5edced6a8dd0 before 8b83efa225f657bfc3656ad8ee8485f9b2de923d. Incorrect Authorization vulnerability in ash-project ash allows Authentication Bypass. This vulnerability is associated with program files lib/ash/policy/policy.ex and program routines 'Elixir.Ash.Policy.Policy':expression/2. This issue affects ash: from 3.6.3 before 3.7.1.

Mon, 06 Apr 2026 16:45:00 +0000


Mon, 20 Oct 2025 20:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 17 Oct 2025 14:00:00 +0000

Type Values Removed Values Added
Description Incorrect Authorization vulnerability in ash-project ash allows Authentication Bypass. This vulnerability is associated with program files lib/ash/policy/policy.ex and program routines 'Elixir.Ash.Policy.Policy':expression/2. This issue affects ash: from pkg:hex/ash@3.6.3 before pkg:hex/ash@3.7.1, from 3.6.3 before 3.7.1, from 79749c2685ea031ebb2de8cf60cc5edced6a8dd0 before 8b83efa225f657bfc3656ad8ee8485f9b2de923d.
Title Authorization bypass when bypass policy condition evaluates to true
First Time appeared Ash-project
Ash-project ash
Weaknesses CWE-863
CPEs cpe:2.3:a:ash-project:ash:*:*:*:*:*:*:*:*
Vendors & Products Ash-project
Ash-project ash
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: EEF

Published:

Updated: 2026-09-22T09:35:27.186Z

Reserved: 2025-05-15T08:40:25.455Z

Link: CVE-2025-48044

cve-icon Vulnrichment

Updated: 2025-10-20T18:42:41.664Z

cve-icon NVD

Status : Deferred

Published: 2025-10-17T14:15:46.403

Modified: 2026-09-22T10:17:08.247

Link: CVE-2025-48044

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T10:30:17Z

Weaknesses