Intel

AIKIDO-2026-684853

ash is vulnerable to Incorrect Authorization

Incorrect AuthorizationCVE-2026-82744 Published 2 days ago

21

Low Risk

This Affects:

ELIXIRash
3.0.0 - 3.32.1
Fixed in 3.32.2
Are you affected? Scan for Free

TL;DR

When a where guard in an Ash.Reactor change step raises, the step skips the change and reports success, the same as a guard that returns false. Untrusted input that makes the guard raise can skip security-relevant changes such as a privilege downgrade, so the action completes as if it succeeded and leaves the record in an unintended state. The fix fails the step closed when a where guard raises.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you use an Ash.Reactor change step with a where guard on untrusted input.

Background info

ash is vulnerable to Incorrect Authorization in versions 3.0.0 - 3.32.1.

How to fix this

Upgrade the ash library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform