{
  "cvss": 8.6,
  "datePublished": "2025-10-17T14:15:46.403",
  "dateUpdated": "2026-09-22T10:17:08.247",
  "description": "Incorrect Authorization vulnerability in ash-project ash allows Authentication Bypass.\n\nThis issue affects ash: from 3.6.3 before 3.7.1.",
  "id": "CVE-2025-48044",
  "raw": {
    "affected": [
      {
        "affectedData": [
          {
            "collectionURL": "https://repo.hex.pm",
            "cpes": [
              "cpe:2.3:a:ash-project:ash:*:*:*:*:*:*:*:*"
            ],
            "defaultStatus": "unaffected",
            "modules": [
              "'Elixir.Ash.Policy.Policy'"
            ],
            "packageName": "ash",
            "packageURL": "pkg:hex/ash",
            "product": "ash",
            "programFiles": [
              "lib/ash/policy/policy.ex"
            ],
            "programRoutines": [
              {
                "name": "'Elixir.Ash.Policy.Policy':expression/2"
              }
            ],
            "repo": "https://github.com/ash-project/ash",
            "vendor": "ash-project",
            "versions": [
              {
                "lessThan": "3.7.1",
                "status": "affected",
                "version": "3.6.3",
                "versionType": "semver"
              }
            ]
          },
          {
            "collectionURL": "https://github.com",
            "cpes": [
              "cpe:2.3:a:ash-project:ash:*:*:*:*:*:*:*:*"
            ],
            "defaultStatus": "unaffected",
            "modules": [
              "'Elixir.Ash.Policy.Policy'"
            ],
            "packageName": "ash-project/ash",
            "packageURL": "pkg:github/ash-project/ash",
            "product": "ash",
            "programFiles": [
              "lib/ash/policy/policy.ex"
            ],
            "programRoutines": [
              {
                "name": "'Elixir.Ash.Policy.Policy':expression/2"
              }
            ],
            "repo": "https://github.com/ash-project/ash",
            "vendor": "ash-project",
            "versions": [
              {
                "lessThan": "8b83efa225f657bfc3656ad8ee8485f9b2de923d",
                "status": "affected",
                "version": "79749c2685ea031ebb2de8cf60cc5edced6a8dd0",
                "versionType": "git"
              }
            ]
          }
        ],
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Incorrect Authorization vulnerability in ash-project ash allows Authentication Bypass.\n\nThis issue affects ash: from 3.6.3 before 3.7.1."
      }
    ],
    "id": "CVE-2025-48044",
    "lastModified": "2026-09-22T10:17:08.247",
    "metrics": {
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 8.6,
            "baseSeverity": "HIGH",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "LOW",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "HIGH",
            "vulnIntegrityImpact": "HIGH",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-48044",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-10-20T18:42:50.579615Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-10-17T14:15:46.403",
    "references": [
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "url": "https://cna.erlef.org/cves/CVE-2025-48044.html"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "url": "https://github.com/ash-project/ash/commit/79749c2685ea031ebb2de8cf60cc5edced6a8dd0"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "url": "https://github.com/ash-project/ash/commit/8b83efa225f657bfc3656ad8ee8485f9b2de923d"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "url": "https://github.com/ash-project/ash/security/advisories/GHSA-pcxq-fjp3-r752"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "url": "https://osv.dev/vulnerability/EEF-CVE-2025-48044"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "url": "https://github.com/ash-project/ash/security/advisories/GHSA-pcxq-fjp3-r752"
      }
    ],
    "sourceIdentifier": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
    "vulnStatus": "Deferred",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-863"
          }
        ],
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "type": "Secondary"
      }
    ]
  },
  "severity": "HIGH",
  "source": "nvd",
  "title": "Incorrect Authorization vulnerability in ash-project ash allows Authentication Bypass.\n\nThis issue affects ash: from ..."
}