SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-82745

MEDIUM · CVSS 5.9 EPSS 0.12% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-01 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The vulnerability allows an attacker to overwrite existing records in the ETS or Mnesia data layers of the ash-project ash by using a create action with a primary key that already exists, bypassing intended access controls. This can lead to unauthorized data manipulation, potentially compromising the integrity of the application’s data. Organizations utilizing affected versions of ash (from 0.4.0 to before 3.32.2) should prioritize patching this issue to prevent potential data loss or corruption.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-82745
Severity
MEDIUM
CVSS
5.9
EPSS
0.12%

Original NVD Description

Improper Access Control vulnerability in ash-project ash lets a create action overwrite an existing record when the ETS or Mnesia data layer is used, because neither enforced primary-key uniqueness on insert. Unlike a SQL data layer, whose unique primary-key constraint rejects a duplicate, the ETS and Mnesia data layers implemented create as a keyed insert that replaces any existing entry with the same primary key (lib/ash/data_layer/ets/ets.ex, lib/ash/data_layer/mnesia/mnesia.ex). An actor who can set the primary key on a create (for example a user-supplied string or integer key) can submit a create whose key matches an existing record and silently overwrite it, destroying and replacing another entity's data without going through the update action or its policies. The fix rejects a create whose primary key already exists with an already-taken error, and only allows duplicates for keyless resources. This issue affects ash: from 0.4.0 before 3.32.2.