Description
Incorrect Authorization vulnerability in ash-project ash_phoenix invokes the SubdomainHook authorization callback with a nil tenant, so tenant-scoped access checks never see the tenant they are meant to enforce.

AshPhoenix.LiveView.SubdomainHook.on_mount/4 attached a handle_params hook to assign the tenant and then immediately called handle_subdomain in the same on_mount. The tenant assign is only written when LiveView later runs handle_params, strictly after on_mount returns, so handle_subdomain read an unset assign and ran as apply(m, f, [socket, nil | a]). A consumer gate that halts when the user does not belong to the tenant instead evaluated nil, either crashing or taking a permissive branch, and it was never re-run once the real subdomain was assigned or on later navigations. The fix runs handle_subdomain inside the handle_params hook with the real tenant on every navigation.

This issue affects ash_phoenix: from 2.1.26 before 2.3.25.
Published: 2026-08-31
Score: 7.6 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises when AshPhoenix’s SubdomainHook handles tenant resolution with a nil tenant value, causing tenant‑scoped authorization checks to receive nil instead of the intended tenant and either crash or follow an inappropriate permissive branch. This incorrect authorization logic leads to a broken access control flaw that could allow attackers to gain unauthorized access to resources or actions that should be confined to a specific tenant, exposing confidential tenant data or enabling integrity violations.

Affected Systems

The affected product is AshPhoenix, available from Ash Project. All releases from version 2.1.26 up to, but not including, 2.3.25 are vulnerable, covering internal versions 2.2.x and 2.3.0–2.3.24.

Risk and Exploitability

The CVSS score is 7.6, indicating a high severity of unauthorized access. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited known exploitation. The likely attack vector is a remote web attacker who can trigger the LiveView mount for a subdomain that provides a nil tenant. If an attacker can reach a LiveView page that uses the SubdomainHook, the flaw may allow bypassing tenant restrictions and accessing protected data without proper authorization.

Generated by OpenCVE AI on August 31, 2026 at 04:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade AshPhoenix to version 2.3.25 or later, where the SubdomainHook calls handle_subdomain with the correct tenant during navigation.
  • If an upgrade is not immediately possible, enforce tenant validation early in LiveView mounts by ensuring the tenant assignment occurs before any authorization gates are consulted.
  • Modify the authorization gate logic to explicitly reject requests when the tenant assign is nil, preventing permissive escalation or crashes.
  • Follow the security advisory GHSA‑39c8‑xcwr‑gqff and monitor the AshProject repository for any additional patches or mitigations.

Generated by OpenCVE AI on August 31, 2026 at 04:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 03:30:00 +0000

Type Values Removed Values Added
Description Incorrect Authorization vulnerability in ash-project ash_phoenix invokes the SubdomainHook authorization callback with a nil tenant, so tenant-scoped access checks never see the tenant they are meant to enforce. AshPhoenix.LiveView.SubdomainHook.on_mount/4 attached a handle_params hook to assign the tenant and then immediately called handle_subdomain in the same on_mount. The tenant assign is only written when LiveView later runs handle_params, strictly after on_mount returns, so handle_subdomain read an unset assign and ran as apply(m, f, [socket, nil | a]). A consumer gate that halts when the user does not belong to the tenant instead evaluated nil, either crashing or taking a permissive branch, and it was never re-run once the real subdomain was assigned or on later navigations. The fix runs handle_subdomain inside the handle_params hook with the real tenant on every navigation. This issue affects ash_phoenix: from 2.1.26 before 2.3.25.
Title Broken access control in AshPhoenix SubdomainHook via a nil tenant in handle_subdomain
First Time appeared Ash-project
Ash-project ash Phoenix
Weaknesses CWE-863
CPEs cpe:2.3:a:ash-project:ash_phoenix:*:*:*:*:*:*:*:*
Vendors & Products Ash-project
Ash-project ash Phoenix
References
Metrics cvssV4_0

{'score': 7.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Ash-project Ash Phoenix
cve-icon MITRE

Status: PUBLISHED

Assigner: EEF

Published:

Updated: 2026-08-31T03:07:57.455Z

Reserved: 2026-08-31T00:59:08.960Z

Link: CVE-2026-82724

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-31T04:17:28.980

Modified: 2026-08-31T04:17:28.980

Link: CVE-2026-82724

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-31T04:30:18Z

Weaknesses