CVE-2026-93477 | ash-project ash up to 3.33.10 Bulk Changeset improper authorization

SecurityVulns

A vulnerability categorized as critical has been discovered in ash-project ash up to 3.33.10. This impacts the function Ash.Actions.Destroy.Bulk.base_changeset/Ash.Actions.Update.Bulk.base_changeset of the component Bulk Changeset. Executing a manipulation can lead to improper authorization.

This vulnerability appears as CVE-2026-93477. The attack may be performed from remote. There is no available exploit.

It is advisable to upgrade the affected component.VulDB Recent EntriesRead More