CVE-2026-101028
Description
Incorrect Authorization vulnerability in ash-project ash allows an actor to infer data in related records they cannot read via Ash.count/2, Ash.exists/2 and Ash.aggregate/3. Ash.Actions.Aggregate.run/4 (lib/ash/actions/aggregate.ex) applied only the root resource's read policy before running the aggregate query. The read path also applies each related resource's read policy to filter and sort references that cross a relationship, directly (for example comments.body) or through an aggregate over one, but the aggregate path skipped that step. A caller whose filter or sort reaches these functions, for example through Ash.Query.filter_input/2, an ash_lua script, or an AshAi tool offering count or exists results, can test conditions against related rows hidden from them and recover their existence and attribute values one query at a time. Ash.read/2 and its page counts are not affected. This issue affects ash: from 2.6.0 before 3.34.6.
References
- https://cna.erlef.org/cves/CVE-2026-101028.html
- https://github.com/ash-project/ash/commit/30eaf1c6e8524527b703e3c4bfeff7967ee0b37c
- https://github.com/ash-project/ash/commit/80936187b27ee94f15cd875affd3141b5cb23185
- https://github.com/ash-project/ash/security/advisories/GHSA-xj24-8f5c-pp5p
- https://osv.dev/vulnerability/EEF-CVE-2026-101028