SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-82724

HIGH · CVSS 7.6 EPSS 0.25% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-31 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The vulnerability arises from incorrect authorization handling in the AshPhoenix framework, where tenant-scoped access checks fail due to the SubdomainHook being invoked with a nil tenant. This can lead to unauthorized access, as the system may either crash or grant permissions erroneously. Organizations using AshPhoenix versions from 2.1.26 to before 2.3.25 should prioritize patching this vulnerability to mitigate potential security risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-82724
Severity
HIGH
CVSS
7.6
EPSS
0.25%

Original NVD Description

Incorrect Authorization vulnerability in ash-project ash_phoenix invokes the SubdomainHook authorization callback with a nil tenant, so tenant-scoped access checks never see the tenant they are meant to enforce. AshPhoenix.LiveView.SubdomainHook.on_mount/4 attached a handle_params hook to assign the tenant and then immediately called handle_subdomain in the same on_mount. The tenant assign is only written when LiveView later runs handle_params, strictly after on_mount returns, so handle_subdomain read an unset assign and ran as apply(m, f, [socket, nil | a]). A consumer gate that halts when the user does not belong to the tenant instead evaluated nil, either crashing or taking a permissive branch, and it was never re-run once the real subdomain was assigned or on later navigations. The fix runs handle_subdomain inside the handle_params hook with the real tenant on every navigation. This issue affects ash_phoenix: from 2.1.26 before 2.3.25.