CVE-2026-101028 | ash-project ash up to 3.34.5 Aggregate aggregate.ex Ash.Actions.Aggregate.run improper authorization
A vulnerability was found in ash-project ash up to 3.34.5. It has been classified as problematic. Affected by this issue is the function Ash.Actions.Aggregate.run of the file lib/ash/actions/aggregate.ex of the component Aggregate. This manipulation causes improper authorization.
This vulnerability is registered as CVE-2026-101028. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is recommended.VulDB Recent EntriesRead More