Junglewise Threat Intelligence

CVE-2026-81853: ash-project ash_admin authorization bypass via user-controlled key

CVE-2026-81853 · Severity: info · Published 2026-08-31

Technologies: Ash-Project Ash Admin. Vendors: Ash-Project.

Executive brief

ash_admin is an administrative interface for the Ash data framework. A vulnerability in its primary-key decoding allows attackers to bypass authorization checks by injecting arbitrary attributes (like API tokens) into record lookups, effectively turning the system into an oracle for guessing sensitive values one character at a time without proper validation.

Technical details

The vulnerability exists in AshAdmin.Helpers.decode_primary_key/2, which deserializes a Base64-encoded Erlang Term Format (ETF) composite key and uses it directly as a lookup filter without validating that decoded keys correspond to actual primary-key fields. Although deserialization guards restrict atom/function injection and nested expressions, they do not constrain which field names are allowed back through the :safe option, permitting any interned attribute name. An attacker can craft a payload encoding %{api_token: "guess"} to splice arbitrary sensitive attributes into the lookup filter, enabling brute-force enumeration of secrets (API tokens, reset tokens, etc.) via equality checks. The fix restricts decoded keys to only legitimate primary-key fields.

Affected products

  • ash-project ash_admin 0.1.0 before 1.3.1

Timeline

  • 2026-08-31: disclosed

References

Related threats