CVE-2026-78216 Details
Description
AshLua exposes Ash read actions to Lua scripts run through an eval action. A read call accepts an operation (list, min, max, first, sum, avg) that builds an ad-hoc Ash.Query.Aggregate over a named field and returns its raw value. Ash field policies redact forbidden fields on returned records (replacing them with %Ash.ForbiddenField{}), but that redaction does not apply to aggregate values. A script could therefore read a field the calling actor's field policies forbid by requesting it as an aggregate instead of as a field. This includes fields that are public? true but restricted per-actor by a field policy, such as sensitive PII. The prior hardening only enforced the exposed-field allow-list (field visibility), which is a separate axis from per-actor field-policy authorization. The fix authorizes the aggregated field against the resource's field policies, so aggregating over a field the actor may not see is refused or scoped to the rows where it is visible. This issue affects ash_lua: from 0.1.0 before 0.2.2.
A vulnerability in AshLua versions 0.1.0 prior to 0.2.2 allows Lua scripts to bypass field policies and access restricted data. This is achieved by using the 'eval' action to perform aggregate operations on fields that are otherwise forbidden, including sensitive personal information. The issue arises because while Ash field policies redact forbidden fields in regular read operations, this redaction does not extend to aggregate values. As a result, a script can access policy-protected fields by requesting them as aggregates, exploiting the gap in per-actor field-policy authorization. The vulnerability is only present when an application exposes an AshLua 'eval' action over a resource with restrictive field policies, yet allows the calling actor to aggregate certain fields.
Users can upgrade to AshLua version 0.2.2 or later, which includes the necessary fix. Instructions for updating can be found on the AshLua Hex.pm page.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 8, 2026CISA-ADP
Assessed Sep 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cna.erlef.org/cves/CVE-2026-78216.html | EEF | AdvisoryBundle |
| https://github.com/ash-project/ash_lua/commit/266a5dcc56d5015b6d316c10606169e753b07450 | EEF | Source CodeVendor |
| https://github.com/ash-project/ash_lua/commit/8675e47cca81f36594083a7e63379bac9e123e72 | EEF | Source CodeVendor |
| https://github.com/ash-project/ash_lua/security/advisories/GHSA-5whv-8rcp-x33j | EEF | AdvisoryRemedyVendor |
| https://osv.dev/vulnerability/EEF-CVE-2026-78216 | EEF | AdvisoryBundle |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1220 | Insufficient Granularity of Access Control | EEF |
Affected Products
| Product | Versions |
|---|---|
| AshLua | >= 0.1.0, < 0.2.2 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 8, 2026 | CVE Modified | CISA-ADP |
| Sep 8, 2026 | New CVE Received | EEF |
Volerion