Description
Incorrect Authorization vulnerability in ash-project ash_sql allows a caller in a schema-based multitenant application to receive aggregate values computed from another tenant's rows.

When an aggregate is computed over a distinct query, AshSql.AggregateQuery.add_single_aggs/5 rebuilds the outer query from query.from.source alone, which is only the {table, schema} tuple and does not carry query.prefix or query.from.prefix. For strategy(:context) multitenancy those hold the tenant schema, so the rebuilt outer query reads the repo's default schema while the inner correlated subquery still reads the tenant schema, and the two are joined only on primary key. The aggregate, and any relationship join added off the prefix-less binding, is then computed against the wrong tenant's rows. The neighbouring limit and exists branches instead wrap the query with subquery/1, which preserves the prefix.

This issue affects ash_sql: from 0.1.0 before 0.7.1.
Published: 2026-08-30
Score: 2.1 Low
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability occurs when a tenant executes an aggregate that includes a DISTINCT clause. The AshSql engine incorrectly rebuilds the outer query, dropping the tenant schema prefix. The result is that the aggregate is calculated against rows belonging to another tenant rather than the caller’s tenant. The attacker receives aggregated values that reflect data from a different tenant, thereby leaking sensitive information. The weakness is identified as CWE-863 (Authorization Control).

Affected Systems

The affected product is AshProject's AshSql database engine. Versions from 0.1.0 up to and including 0.7.0 contain the flaw. Any installation relying on these releases is vulnerable until the upgrade to 0.7.1 or later is applied.

Risk and Exploitability

The CVSS score of 2.1 indicates a low severity impact. Because the exploit requires the attacker to invoke a specific aggregate query in a tenant context, the difficulty is moderate, and no public exploits are documented. The EPSS score is unavailable and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the likely attack vector is through the application layer, requiring legitimate access to the database API or user privileges that allow execution of aggregate operations.

Generated by OpenCVE AI on August 30, 2026 at 13:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade AshSql to version 0.7.1 or newer, which contains the fix that preserves tenant schema prefixes during aggregate queries.
  • Verify that the upgraded database is correctly configured to enforce tenant isolation in all queries.
  • Review or audit custom aggregator functions that might bypass the fixed logic and run tests for cross‑tenant data leakage.

Generated by OpenCVE AI on August 30, 2026 at 13:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 30 Aug 2026 12:00:00 +0000

Type Values Removed Values Added
Description Incorrect Authorization vulnerability in ash-project ash_sql allows a caller in a schema-based multitenant application to receive aggregate values computed from another tenant's rows. When an aggregate is computed over a distinct query, AshSql.AggregateQuery.add_single_aggs/5 rebuilds the outer query from query.from.source alone, which is only the {table, schema} tuple and does not carry query.prefix or query.from.prefix. For strategy(:context) multitenancy those hold the tenant schema, so the rebuilt outer query reads the repo's default schema while the inner correlated subquery still reads the tenant schema, and the two are joined only on primary key. The aggregate, and any relationship join added off the prefix-less binding, is then computed against the wrong tenant's rows. The neighbouring limit and exists branches instead wrap the query with subquery/1, which preserves the prefix. This issue affects ash_sql: from 0.1.0 before 0.7.1.
Title Distinct-query aggregate drops the tenant schema prefix, leaking across tenants in AshSql
First Time appeared Ash-project
Ash-project ash Sql
Weaknesses CWE-863
CPEs cpe:2.3:a:ash-project:ash_sql:*:*:*:*:*:*:*:*
Vendors & Products Ash-project
Ash-project ash Sql
References
Metrics cvssV4_0

{'score': 2.1, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Ash-project Ash Sql
cve-icon MITRE

Status: PUBLISHED

Assigner: EEF

Published:

Updated: 2026-08-30T11:56:52.921Z

Reserved: 2026-08-30T02:30:02.111Z

Link: CVE-2026-81318

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-30T12:17:19.030

Modified: 2026-08-30T12:17:19.030

Link: CVE-2026-81318

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-30T13:30:05Z

Weaknesses