Authorization Bypass Through User-Controlled Key vulnerability in ash-project ash_phoenix lets an attacker who controls filter form parameters filter across relationships the resource author marked non-public, turning the returned rows into a boolean oracle over private related data.
AshPhoenix.FilterForm resolved every relationship hop in the user-supplied path with Ash.Resource.Info.related/2, which traverses private relationships, and only checked the terminal field for publicity. parsepathandfield/2 also rewrote a field naming a relationship into an extra path segment, so field=someprivaterel was accepted too. Both path and field come straight from form params, and the resulting ref went to Ash.Query.dofilter/2 without the public-only enforcement of Ash.Filter.parseinput/2. The fix resolves each hop with Ash.Resource.Info.publicrelationship/2, rejecting the first non-public hop, and requires the terminal field to be public.
This issue affects ash_phoenix: from 0.6.0-rc.1 before 2.3.25.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/82xxx/CVE-2026-82725.json",
"unresolved_ranges": [
{
"source": "AFFECTED_FIELD",
"extracted_events": [
{
"introduced": "06875682999938f607c970e71b6a80af90e18b3d"
},
{
"fixed": "a3691a3cb0947e8f2dc2c3cbff138a3e6197a15b"
}
]
}
],
"cna_assigner": "EEF",
"cwe_ids": [
"CWE-639"
]
}