← العودة للجدول
CVE-2026-82747
CVE-2026-82747 — Incorrect Authorization vulnerability in ash-project ash returns records that a
📅 2026-09-01
🟠 High 🔥 No NVD Exploit Exploit

📋 الوصف الكامل

Incorrect Authorization vulnerability in ash-project ash returns records that a runtime read policy denies to any actor. When a resource has an access_type :runtime read policy (a check evaluated per record rather than compiled to a filter), Ash.Policy.Authorizer decides each record in check_result/1 (lib/ash/policy/authorizer/authorizer.ex) by discarding impossible policy scenarios and inspectin

💻 الأنظمة المتأثرة

Apple iOS

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2026-82747

📡 المصدر

NVD

✅ الحلول والتخفيف

Refer to CVE-2026-82747 NVD advisory

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ← 🔍 Valters IT ←