← العودة للجدول
CVE-2026-82748
CVE-2026-82748 — Incorrect Authorization vulnerability in ash-project ash authorizes an aggregate
📅 2026-09-01
🟡 Medium 🔥 No NVD Vulnerability Vulnerability

📋 الوصف الكامل

Incorrect Authorization vulnerability in ash-project ash authorizes an aggregate under one read action while computing it under another, so an aggregate can run with policies that do not match the action it was authorized against. Ash.Actions.Aggregate groups aggregates by their {authorize?, read_action} and authorizes each group under that read action, but when building the data query it selecte

💻 الأنظمة المتأثرة

⚠️ نوع التهديد

Vulnerability

🔗 CVE ID

CVE-2026-82748

📡 المصدر

NVD

✅ الحلول والتخفيف

Refer to CVE-2026-82748 NVD advisory

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ← 🔍 Valters IT ←