Answer in brief
CVE-2026-101028 records a Medium severity (CVSS 6.0) vulnerability in Ash.count, Ash.exists and Ash.aggregate skip related resources' read policies in filters and sorts. The current sources do not mark it as known exploited. The current feed maps ash-project/ash (generic), ash-project/ash-project/ash (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 6.0. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps ash-project/ash (generic), ash-project/ash-project/ash (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| ash-project/ashgeneric | >=2.6.0 <3.34.6 | 3.34.6 |
| ash-project/ash-project/ashgeneric | >=30eaf1c6e8524527b703e3c4bfeff7967ee0b37c <80936187b27ee94f15cd875affd3141b5cb23185 | 80936187b27ee94f15cd875affd3141b5cb23185 |
Published upstream
Oct 9, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 9, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 9, 2026
Incorrect Authorization vulnerability in ash-project ash allows an actor to infer data in related records they cannot read via Ash.count/2, Ash.exists/2 and Ash.aggregate/3. Ash.Actions.Aggregate.run/4 (lib/ash/actions/aggregate.ex) applied only the root resource's read policy before running the aggregate query. The read path also applies each related resource's read policy to filter and sort references that cross a relationship, directly (for example comments.body) or through an aggregate over one, but the aggregate path skipped that step. A caller whose filter or sort reaches these functions, for example through Ash.Query.filter_input/2, an ash_lua script, or an AshAi tool offering count or exists results, can test conditions against related rows hidden from them and recover their existence and attribute values one query at a time. Ash.read/2 and its page counts are not affected. This issue affects ash: from 2.6.0 before 3.34.6.
Quoted source text, attributed separately from HOL analysis.