UNKNOWNhex

Ash.update_many/4 atomic path skips resource policy authorization, allowing updates to forbidden records

Ash.update_many/4 atomic path skips resource policy authorization, allowing updates to forbidden records

CVE-2026-82746Published 5 days agoUpdated 5 days agoSource: OSV

Affected packages

  • ash

Exploit signal

Known exploited (CISA KEV)
No
EPSS score
EPSS percentile

EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.

Ash.update_many/4 atomic path skips resource policy authorization, allowing updates to forbidden records | HackTribune