Get real-time updates on Telegram
CVE-2026-101028: ash 2.6.0 to before 3.34.6
Affected technology
ash · 2.6.0 to before 3.34.6
ash-project
ash · 30eaf1c6e8524527b703e3c4bfeff7967ee0b37c to before 80936187b27ee94f15cd875affd3141b5cb23185
ash-project
Component: 'Elixir.Ash.Actions.Aggregate', 'Elixir.Ash'
Function: 'Elixir.Ash.Actions.Aggregate':run/4, 'Elixir.Ash':count/2, 'Elixir.Ash':exists/2, 'Elixir.Ash':aggregate/3
File: lib/ash/actions/aggregate.ex, lib/ash.ex
Attack conditions (Source advisory, CVSS 4.0): Network (remote) · Low privileges required · No user interaction required
What an attacker can do
Source advisory’s CVSS 4.0 assessment (base score 6.0/10) rates confidentiality impact as high; integrity and availability impact as none. The description does not specify what an attacker can achieve beyond these rated impacts.
- CWE
- CWE-863
- KEV
- no
Provenance
- NVD CVE API 2.0 · Source record · observed 2026-10-09 12:21:30.679837+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2026-101028.html