Description
Incorrect Authorization vulnerability in ash-project ash allows an actor to infer data in related records they cannot read via Ash.count/2, Ash.exists/2 and Ash.aggregate/3.

Ash.Actions.Aggregate.run/4 (lib/ash/actions/aggregate.ex) applied only the root resource's read policy before running the aggregate query. The read path also applies each related resource's read policy to filter and sort references that cross a relationship, directly (for example comments.body) or through an aggregate over one, but the aggregate path skipped that step. A caller whose filter or sort reaches these functions, for example through Ash.Query.filter_input/2, an ash_lua script, or an AshAi tool offering count or exists results, can test conditions against related rows hidden from them and recover their existence and attribute values one query at a time. Ash.read/2 and its page counts are not affected.

This issue affects ash: from 2.6.0 before 3.34.6.
Published: 2026-10-09
Score: 6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Data Inference
Action: Apply Patch
AI Analysis

Impact

The vulnerability in the Ash framework causes the read policy of related resources to be omitted when executing aggregate, count, or exists operations. This omission lets an attacker apply filters or sort criteria that touch hidden related data, thereby testing conditions against records they cannot normally read. The attacker can then deduce the existence and specific attribute values of those hidden rows one query at a time, leaking confidential information about related resources.

Affected Systems

Systems running Ash versions 2.6.0 through 3.34.5 are susceptible. The issue affects the ash-project:ash product as listed by the CNA and is documented under the CA version range before 3.34.6. No other versions are referenced as affected.

Risk and Exploitability

The CVSS score of 6 indicates moderate severity. EPSS is not available, and the vulnerability is not currently listed in CISA KEV, suggesting a lower immediate exploitation probability. The likely attack vector is through legitimate API calls to functions such as Ash.count/2, Ash.exists/2, or Ash.aggregate/3, or via custom scripts that leverage these functions. Once accessed, an attacker can infer sensitive data from related resources, impacting confidentiality without affecting read/authorization counts exposed through Ash.read/2.

Generated by OpenCVE AI on October 9, 2026 at 08:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Ash to version 3.34.6 or later to receive the patch that restores proper read policy enforcement in aggregates
  • Review custom aggregate, count, and exists usage in the application to ensure related resource read policies are explicitly checked, and correct any missing checks
  • If the patch cannot be applied immediately, disable or restrict exposure of these functions to trusted roles only, preventing unauthorized inference until remediation is completed

Generated by OpenCVE AI on October 9, 2026 at 08:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 07:15:00 +0000

Type Values Removed Values Added
Description Incorrect Authorization vulnerability in ash-project ash allows an actor to infer data in related records they cannot read via Ash.count/2, Ash.exists/2 and Ash.aggregate/3. Ash.Actions.Aggregate.run/4 (lib/ash/actions/aggregate.ex) applied only the root resource's read policy before running the aggregate query. The read path also applies each related resource's read policy to filter and sort references that cross a relationship, directly (for example comments.body) or through an aggregate over one, but the aggregate path skipped that step. A caller whose filter or sort reaches these functions, for example through Ash.Query.filter_input/2, an ash_lua script, or an AshAi tool offering count or exists results, can test conditions against related rows hidden from them and recover their existence and attribute values one query at a time. Ash.read/2 and its page counts are not affected. This issue affects ash: from 2.6.0 before 3.34.6.
Title Ash.count, Ash.exists and Ash.aggregate skip related resources' read policies in filters and sorts
First Time appeared Ash-project
Ash-project ash
Weaknesses CWE-863
CPEs cpe:2.3:a:ash-project:ash:*:*:*:*:*:*:*:*
Vendors & Products Ash-project
Ash-project ash
References
Metrics cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: EEF

Published:

Updated: 2026-10-09T07:01:06.470Z

Reserved: 2026-10-08T15:45:02.376Z

Link: CVE-2026-101028

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-09T07:17:17.627

Modified: 2026-10-09T17:07:31.693

Link: CVE-2026-101028

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T09:00:03Z

Weaknesses