Junglewise Threat Intelligence

CVE-2026-82724: ash-project ash_phoenix authorization bypass in SubdomainHook

CVE-2026-82724 · Severity: info · Published 2026-08-31

Technologies: Ash-Project Ash Phoenix. Vendors: Ash-Project.

Executive brief

ash_phoenix is a Phoenix/LiveView integration library for the Ash data framework, used to build web applications with multi-tenant support. The vulnerability allows tenant-scoped authorization checks to be bypassed by invoking them with a nil tenant value, potentially granting unauthorized access to data across tenant boundaries. This breaks the core tenant isolation mechanism that protects customer data in multi-tenant applications.

Technical details

The vulnerability is an incorrect authorization/timing flaw in AshPhoenix.LiveView.SubdomainHook.on_mount/4. The hook attempts to assign the tenant and immediately call handle_subdomain within on_mount, but LiveView does not execute handle_params (where the tenant assign is set) until after on_mount returns. Consequently, handle_subdomain runs with a nil tenant, causing authorization checks that verify tenant membership to either crash or take a permissive default path. These checks are never re-evaluated once the real tenant is assigned or on subsequent navigations. The fix moves handle_subdomain invocation into the handle_params hook where the tenant is properly available on every navigation. Affected versions: ash_phoenix 2.1.26 before 2.3.25.

Affected products

  • ash-project ash_phoenix 2.1.26 to before 2.3.25

Timeline

  • 2026-08-31: disclosed

References

Related threats