PULSE
FEED
ransombarracuda reclama a Ministarstvo poljoprivrede, šumarstva i ribarstva · HR · Agriculture and Food Productionransomsilentransomgroup reclama a O'Hagan Meyer · Professional Servicesransomnetrunner reclama a Mid Atlantic Gynecologic Oncology and Pelvic Surgery Associates · US · Healthcareransomumbra reclama a SOCOCO · FR · Technologyransomeclipse reclama a dipecarr.com.br · BR · Manufacturingransomqilin reclama a MCM Telecom · MX · Technologyransomsilentransomgroup reclama a Baker McKenzie · US · Professional Servicesransomumbra reclama a Manipal Academy of Higher Edu · IN · Educationransomumbra reclama a IIT Roorkee · IN · Educationransomumbra reclama a FSE, Cairo University · EG · Educationransompayload reclama a Boullard Musique · FR · Retail & E-Commerceransomeclipse reclama a simplexengg.in · IN · Manufacturingransomeclipse reclama a sanjoseattorneys.com · US · Professional Servicesransomsilentransomgroup reclama a Andersen Group Inc. · Professional Servicesransombarracuda reclama a Ministarstvo poljoprivrede, šumarstva i ribarstva · HR · Agriculture and Food Productionransomsilentransomgroup reclama a O'Hagan Meyer · Professional Servicesransomnetrunner reclama a Mid Atlantic Gynecologic Oncology and Pelvic Surgery Associates · US · Healthcareransomumbra reclama a SOCOCO · FR · Technologyransomeclipse reclama a dipecarr.com.br · BR · Manufacturingransomqilin reclama a MCM Telecom · MX · Technologyransomsilentransomgroup reclama a Baker McKenzie · US · Professional Servicesransomumbra reclama a Manipal Academy of Higher Edu · IN · Educationransomumbra reclama a IIT Roorkee · IN · Educationransomumbra reclama a FSE, Cairo University · EG · Educationransompayload reclama a Boullard Musique · FR · Retail & E-Commerceransomeclipse reclama a simplexengg.in · IN · Manufacturingransomeclipse reclama a sanjoseattorneys.com · US · Professional Servicesransomsilentransomgroup reclama a Andersen Group Inc. · Professional Services
← Todos los CVEs
CVE Watch9 oct 2026

CVE-2026-101028

Incorrect Authorization vulnerability in ash-project ash allows an actor to infer data in related records they cannot read via Ash.count/2,

CVSS

—

Sin CVSS

EPSS

—

KEV

—

Exploit Today

—

0-100

Publicado: 9 oct 2026 · Última mod.: 9 oct 2026 · CWE-863

EPSS · 30d

Sin historial EPSS suficiente todavía.

Descripción técnica

Incorrect Authorization vulnerability in ash-project ash allows an actor to infer data in related records they cannot read via Ash.count/2, Ash.exists/2 and Ash.aggregate/3. Ash.Actions.Aggregate.run/4 (lib/ash/actions/aggregate.ex) applied only the root resource's read policy before running the aggregate query. The read path also applies each related resource's read policy to filter and sort references that cross a relationship, directly (for example comments.body) or through an aggregate over one, but the aggregate path skipped that step. A caller whose filter or sort reaches these functions, for example through Ash.Query.filter_input/2, an ash_lua script, or an AshAi tool offering count or exists results, can test conditions against related rows hidden from them and recover their existence and attribute values one query at a time. Ash.read/2 and its page counts are not affected. This issue affects ash: from 2.6.0 before 3.34.6.

Referencias oficiales
CVEs relacionados
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-1077287.5 ALT
—
——0Strawberry GraphQL is a library for creating GraphQL APIs. From 0.217.0 until 0.326.1, PermissionExtension.resolve() on a synchronous field resolver evaluates the result of has_permission() for truthiness. When a custom permission declares has_permission() as a normal function but returns an awaitable, supports_sync does not classify it as asynchronous, the awaitable is not awaited, and its inherently truthy object value permits the protected resolver to run even when the result would resolve to false. This affects synchronous field resolvers under both execute_sync() and execute(); permissions declared with async def has_permission() and synchronous permissions returning a boolean are not affected. This issue is fixed in version 0.326.1.11h
CVE-2026-1077827.8 ALT
—
——0System Informer before 4.0.26241.138 contains an incorrect authorization vulnerability in the phsvc helper that allows local attackers to reach privileged APIs by connecting from any Authenticode-signed process. Attackers can load code into a Microsoft-signed host like rundll32.exe, connect to SiSvcApiPort, and call PhSvcApiCreateService to execute code as SYSTEM.13h
CVE-2026-1077064.3 MED
—
——0Dolibarr ERP CRM before 24.0.2 contains an incorrect authorization vulnerability in htdocs/core/ajax/updateextrafield.php that checks only read permission before writing extrafield values. Authenticated users with read-only access can POST objectType, objectId, field and value parameters to persistently modify extrafields on viewable third parties, products, members, projects or contacts.13h
CVE-2026-97147—
—
——0In OpenStack Mistral through 23.0.0, several of the v2 API write paths resolve the target object with a query that can return another project's resource, then write to it. An authenticated project member can use this to rewrite and un-publish another project's public action definitions and environments. A project administrator can create a workbook whose embedded ad-hoc action or workflow name collides with a resource of another project, which moves that resource into the caller's project and causes the original owner's subsequent updates of it to fail with server errors. Only deployments exposing the Mistral API are affected.13h
CVE-2026-93861—
—
——0In OpenStack Mistral through 23.0.0, the workflow membership API lets a project that has accepted a share of another project's private workflow create a further membership naming a third project. The new membership row is created with its project_id defaulted to the accepting project rather than the original workflow owner, and thus the owner can neither see nor delete it. The third project can accept this membership (that it had not actually been granted by the owner), and then read and execute the owner's private workflow; only the accepting (not the owning) project can later revoke that access.13h
CVE-2026-1073366.5 MED
—
——0Malcolm's front nginx reverse proxy defines a "Dashboards → Arkime shortcut" location using a case-insensitive regex matcher but a case-sensitive rewrite. A request whose path segment is not exact-lowercase (for example /IDDASH2ARK/...) enters the location (the matcher fires) but evades the rewrite (no redirect is issued), so nginx falls through to the location's proxy_pass to the Arkime backend. That location is the one proxied location in the shipped config that does not include the per-location authentication file, so the request reaches Arkime unauthenticated. The same location also forwards a client-supplied X-Forwarded-User header un-overwritten, and Arkime is configured to trust X-Forwarded-User as the authenticated username — so an unauthenticated network caller can reach the Arkime backend while supplying a forged, auto-provisioned identity.13h