CVE-2026-82744 | Ash-Project Ash 3.0.0-rc.17/3.32.1 Reactor change_step.ex Ash.Reactor.ChangeStep.apply_where_clauses access control

SecurityVulns

A vulnerability classified as problematic has been found in Ash-Project Ash 3.0.0-rc.17/3.32.1. Affected by this vulnerability is the function Ash.Reactor.ChangeStep.apply_where_clauses of the file lib/ash/reactor/steps/change_step.ex of the component Reactor. The manipulation leads to improper access controls.

This vulnerability is traded as CVE-2026-82744. It is possible to initiate the attack remotely. There is no exploit available.

It is recommended to upgrade the affected component.VulDB Recent EntriesRead More