← العودة للجدول
CVE-2026-82730
CVE-2026-82730 — Incorrect Authorization vulnerability in ash-project ash_typescript allows an un
📅 2026-09-01
🟠 High 🔥 No NVD Vulnerability Vulnerability

📋 الوصف الكامل

Incorrect Authorization vulnerability in ash-project ash_typescript allows an unauthorized RPC caller to read attribute values that Ash field policies denied. When a field policy denies an attribute, Ash substitutes %Ash.ForbiddenField{}, which retains the real value in original_value because embedded resources must remain writable, and hides it from Inspect rather than removing it. AshTypescript

💻 الأنظمة المتأثرة

⚠️ نوع التهديد

Vulnerability

🔗 CVE ID

CVE-2026-82730

📡 المصدر

NVD

✅ الحلول والتخفيف

Refer to CVE-2026-82730 NVD advisory

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ← 🔍 Valters IT ←