Intel

AIKIDO-2026-771360

ash is vulnerable to Improper Access Control

Improper Access ControlCVE-2026-82745 Published 2 days ago

59

Medium Risk

This Affects:

ELIXIRash
0.4.0 - 3.32.1
Fixed in 3.32.2
Are you affected? Scan for Free

TL;DR

The ETS and Mnesia data layers write new records without checking whether the primary key already exists. A create action that supplies an existing primary key overwrites the stored record instead of failing. When primary keys are client controlled, create actions can change existing rows even where authorization policies are enforced. The fix rejects duplicate primary keys on create in both data layers.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you use the ETS or Mnesia data layer with client supplied primary keys on create actions.

Background info

ash is vulnerable to Improper Access Control in versions 0.4.0 - 3.32.1.

How to fix this

Upgrade the ash library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform