Incorrect Authorization vulnerability in ash-project ash_sql allows a caller to receive an aggregate value computed over rows a more restrictive filter should have excluded, disclosing counts, sums, or lists across an authorization or tenancy boundary.
AshSql.Aggregate.different_queries?/2 reports two aggregate queries as different only when their filter and their sort both differ. Aggregate queries rarely carry a sort, so two aggregates that share a name but carry entirely different filters compare as identical. The colliding aggregate keeps its name and is treated as already computed, and select_aggregates returns the first-registered variant's value. The same name reaches the builder twice with different filters when actor or tenant context is stamped into each aggregate's query, so a narrowly filtered aggregate can be served the value of a previously registered broad one.
This issue affects ash_sql: from 0.1.0 before 0.7.1.
Metrics
Affected Vendors & Products
References
History
Sun, 30 Aug 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Incorrect Authorization vulnerability in ash-project ash_sql allows a caller to receive an aggregate value computed over rows a more restrictive filter should have excluded, disclosing counts, sums, or lists across an authorization or tenancy boundary. AshSql.Aggregate.different_queries?/2 reports two aggregate queries as different only when their filter and their sort both differ. Aggregate queries rarely carry a sort, so two aggregates that share a name but carry entirely different filters compare as identical. The colliding aggregate keeps its name and is treated as already computed, and select_aggregates returns the first-registered variant's value. The same name reaches the builder twice with different filters when actor or tenant context is stamped into each aggregate's query, so a narrowly filtered aggregate can be served the value of a previously registered broad one. This issue affects ash_sql: from 0.1.0 before 0.7.1. | |
| Title | Same-named aggregates with differing filters are conflated in AshSql | |
| First Time appeared |
Ash-project
Ash-project ash Sql |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:ash-project:ash_sql:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Ash-project
Ash-project ash Sql |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: EEF
Published:
Updated: 2026-08-30T11:59:41.945Z
Reserved: 2026-08-29T23:30:01.223Z
Link: CVE-2026-81316
No data.
Status : Received
Published: 2026-08-30T12:17:18.870
Modified: 2026-08-30T12:17:18.870
Link: CVE-2026-81316
No data.
OpenCVE Enrichment
Updated: 2026-08-30T13:30:05Z