CVE-2026-93477
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash allows a user to set the value of a private action argument on the bulk destroy and bulk update paths.
Action arguments declared with public?: false are meant to be set only by trusted server-side code (for example via Ash.Changeset.set_private_argument/3) and must not be settable from end-user input. CVE-2026-55736 fixed the non-bulk changeset path to strip private arguments from user-supplied parameter maps, but the bulk destroy and bulk update paths were not covered.
Ash.Actions.Destroy.Bulk.base_changeset/5 and Ash.Actions.Update.Bulk.base_changeset/5 match every key in the caller-supplied parameter map against all of the action's arguments with no public? check, then apply the matches to the base changeset.
Leer descripción completaMostrar menos
A caller who can submit parameters to a bulk destroy or bulk update action (for example through AshJsonApi, AshGraphql, or a controller that forwards request parameters to Ash.bulk_destroy/4 or Ash.bulk_update/4) can therefore set any private argument of that action, including one referenced by an arg(...) template in the action's changes or validations. Depending on how the application uses the argument (for example an acting_user_id driving authorization or record ownership, or audit metadata), this can lead to an integrity violation or privilege escalation.
The fix requires public? in the argument matching on both bulk paths; private arguments remain settable server-side via the :private_arguments option.
This issue affects ash: from 2.17.15 before 3.33.11.
CVSS
- Versión: 4.0
- Vector: CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Puntuación base: 5.9
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.20%
- Percentil entre todas las CVEs puntuadas: 8
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1068Exploitation for Privilege Escalationprivilege escalation85 % - Impacto principal
T1078Valid Accountsstealth · persistence · privilege escalation · initial access80 % - Impacto secundario
T1565.002Transmitted Data Manipulationimpact75 %
Escalada de privilegios mediante inyección de argumentos privados en acciones bulk (destroy/update) sin validación de permisos; permite suplantación de identidad o modificación no autorizada de datos en aplicaciones Ash.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-915
Referencias
- https://cna.erlef.org/cves/CVE-2026-93477.html
- https://github.com/ash-project/ash/commit/6b7ac53a0a2532291eb940d7beaf0fbb2da6fc4f
- https://github.com/ash-project/ash/commit/8c17434803b2e91de522bdfbd0ca918e5d5898df
- https://github.com/ash-project/ash/security/advisories/GHSA-c2p4-p7q6-hr2j
- https://osv.dev/vulnerability/EEF-CVE-2026-93477
- https://github.com/ash-project/ash/security/advisories/GHSA-c2p4-p7q6-hr2j
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-93477",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-93477",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-09-25T13:26:14.200048Z"
}
}
],
"cvssMetricV40": [
{
"type": "Secondary",
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
"cvssData": {
"Safety": "NOT_DEFINED",
"version": "4.0",
"Recovery": "NOT_DEFINED",
"baseScore": 5.9,
"Automatable": "NOT_DEFINED",
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"exploitMaturity": "NOT_DEFINED",
"providerUrgency": "NOT_DEFINED",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"privilegesRequired": "NONE",
"subIntegrityImpact": "NONE",
"vulnIntegrityImpact": "HIGH",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"vulnAvailabilityImpact": "NONE",
"availabilityRequirement": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"subConfidentialityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"confidentialityRequirement": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"vulnerabilityResponseEffort": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED"
}
}
]
},
"affected": [
{
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
"affectedData": [
{
"cpes": [
"cpe:2.3:a:ash-project:ash:*:*:*:*:*:*:*:*"
],
"repo": "https://github.com/ash-project/ash",
"vendor": "ash-project",
"modules": [
"'Elixir.Ash.Actions.Destroy.Bulk'",
"'Elixir.Ash.Actions.Update.Bulk'"
],
"product": "ash",
"versions": [
{
"status": "affected",
"version": "2.17.15",
"lessThan": "3.33.11",
"versionType": "semver"
}
],
"packageURL": "pkg:hex/ash",
"packageName": "ash",
"programFiles": [
"lib/ash/actions/destroy/bulk.ex",
"lib/ash/actions/update/bulk.ex"
],
"collectionURL": "https://repo.hex.pm",
"defaultStatus": "unaffected",
"programRoutines": [
{
"name": "'Elixir.Ash.Actions.Destroy.Bulk':base_changeset/5"
},
{
"name": "'Elixir.Ash.Actions.Update.Bulk':base_changeset/5"
}
]
},
{
"cpes": [
"cpe:2.3:a:ash-project:ash:*:*:*:*:*:*:*:*"
],
"repo": "https://github.com/ash-project/ash",
"vendor": "ash-project",
"modules": [
"'Elixir.Ash.Actions.Destroy.Bulk'",
"'Elixir.Ash.Actions.Update.Bulk'"
],
"product": "ash",
"versions": [
{
"status": "affected",
"version": "8c17434803b2e91de522bdfbd0ca918e5d5898df",
"lessThan": "6b7ac53a0a2532291eb940d7beaf0fbb2da6fc4f",
"versionType": "git"
}
],
"packageURL": "pkg:github/ash-project/ash",
"packageName": "ash-project/ash",
"programFiles": [
"lib/ash/actions/destroy/bulk.ex",
"lib/ash/actions/update/bulk.ex"
],
"collectionURL": "https://github.com",
"defaultStatus": "unaffected",
"programRoutines": [
{
"name": "'Elixir.Ash.Actions.Destroy.Bulk':base_changeset/5"
},
{
"name": "'Elixir.Ash.Actions.Update.Bulk':base_changeset/5"
}
]
}
]
}
],
"published": "2026-09-25T07:16:56.163",
"references": [
{
"url": "https://cna.erlef.org/cves/CVE-2026-93477.html",
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
},
{
"url": "https://github.com/ash-project/ash/commit/6b7ac53a0a2532291eb940d7beaf0fbb2da6fc4f",
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
},
{
"url": "https://github.com/ash-project/ash/commit/8c17434803b2e91de522bdfbd0ca918e5d5898df",
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
},
{
"url": "https://github.com/ash-project/ash/security/advisories/GHSA-c2p4-p7q6-hr2j",
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
},
{
"url": "https://osv.dev/vulnerability/EEF-CVE-2026-93477",
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
},
{
"url": "https://github.com/ash-project/ash/security/advisories/GHSA-c2p4-p7q6-hr2j",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
"description": [
{
"lang": "en",
"value": "CWE-915"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash allows a user to set the value of a private action argument on the bulk destroy and bulk update paths.\n\nAction arguments declared with public?: false are meant to be set only by trusted server-side code (for example via Ash.Changeset.set_private_argument/3) and must not be settable from end-user input. CVE-2026-55736 fixed the non-bulk changeset path to strip private arguments from user-supplied parameter maps, but the bulk destroy and bulk update paths were not covered.\n\nAsh.Actions.Destroy.Bulk.base_changeset/5 and Ash.Actions.Update.Bulk.base_changeset/5 match every key in the caller-supplied parameter map against all of the action's arguments with no public? check, then apply the matches to the base changeset. A caller who can submit parameters to a bulk destroy or bulk update action (for example through AshJsonApi, AshGraphql, or a controller that forwards request parameters to Ash.bulk_destroy/4 or Ash.bulk_update/4) can therefore set any private argument of that action, including one referenced by an arg(...) template in the action's changes or validations. Depending on how the application uses the argument (for example an acting_user_id driving authorization or record ownership, or audit metadata), this can lead to an integrity violation or privilege escalation.\n\nThe fix requires public? in the argument matching on both bulk paths; private arguments remain settable server-side via the :private_arguments option.\n\nThis issue affects ash: from 2.17.15 before 3.33.11."
}
],
"lastModified": "2026-09-25T14:17:23.093",
"sourceIdentifier": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
}