CYBER CODE RED

Get real-time updates on Telegram

Verified

CVE-2026-101028: ash 2.6.0 to before 3.34.6

Affected technology

ash · 2.6.0 to before 3.34.6
ash-project

ash · 30eaf1c6e8524527b703e3c4bfeff7967ee0b37c to before 80936187b27ee94f15cd875affd3141b5cb23185
ash-project

Component: 'Elixir.Ash.Actions.Aggregate', 'Elixir.Ash'
Function: 'Elixir.Ash.Actions.Aggregate':run/4, 'Elixir.Ash':count/2, 'Elixir.Ash':exists/2, 'Elixir.Ash':aggregate/3
File: lib/ash/actions/aggregate.ex, lib/ash.ex

Attack conditions (Source advisory, CVSS 4.0): Network (remote) · Low privileges required · No user interaction required

What an attacker can do

Source advisory’s CVSS 4.0 assessment (base score 6.0/10) rates confidentiality impact as high; integrity and availability impact as none. The description does not specify what an attacker can achieve beyond these rated impacts.

Published

CWE
CWE-863
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-101028.html