Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-101028— Ash.count, Ash.exists and Ash.aggregate skip related resources' read policies in filters and sorts

Quick assessment

Affected
ash-project ash
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

以下是该漏洞描述信息的中文翻译: ash-project 的 ash 存在一个授权不正确(Incorrect Authorization)漏洞。攻击者可以通过 Ash.count/2、Ash.exists/2 和 Ash.aggregate/3 推断出其无权读取的相关记录中的数据。 在运行聚合查询之前,Ash.Actions.Aggregate.run/4(lib/ash/actions/aggregate.ex)仅应用了根资源(root resource)的读取策略(read policy)。而在正常读取路径中,

CVSS 6.0 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-101028

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Ash.count, Ash.exists and Ash.aggregate skip related resources' read policies in filters and sorts
Source: CVE Program / CVE List V5
Vulnerability Description
Incorrect Authorization vulnerability in ash-project ash allows an actor to infer data in related records they cannot read via Ash.count/2, Ash.exists/2 and Ash.aggregate/3. Ash.Actions.Aggregate.run/4 (lib/ash/actions/aggregate.ex) applied only the root resource's read policy before running the aggregate query. The read path also applies each related resource's read policy to filter and sort references that cross a relationship, directly (for example comments.body) or through an aggregate over one, but the aggregate path skipped that step. A caller whose filter or sort reaches these functions, for example through Ash.Query.filter_input/2, an ash_lua script, or an AshAi tool offering count or exists results, can test conditions against related rows hidden from them and recover their existence and attribute values one query at a time. Ash.read/2 and its page counts are not affected. This issue affects ash: from 2.6.0 before 3.34.6.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制不正确
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
ash-project ash 2.6.0 ~ 3.34.6 cpe:2.3:a:ash-project:ash:*:*:*:*:*:*:*:*
ash-project ash 30eaf1c6e8524527b703e3c4bfeff7967ee0b37c ~ 80936187b27ee94f15cd875affd3141b5cb23185 cpe:2.3:a:ash-project:ash:*:*:*:*:*:*:*:*

II. Public POCs for CVE-2026-101028

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-101028

请登录查看更多情报信息。

Other References for CVE-2026-101028 (5)

IV. Related Vulnerabilities

V. Comments for CVE-2026-101028

No comments yet


Leave a comment