---
cve: "CVE-2026-82681"
severity: "LOW"
cvss: 3.1
epss: "5%"
vendor: "Generic Security"
kev: false
exploited: false
published: "2026-08-31 03:16:43"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-03T03:50:42+02:00"
---

# CVE-2026-82681

> 3.1 LOW

## Beschreibung

Improper Encoding or Escaping of Output vulnerability in ash-project ash_admin lets an attacker who controls a record's string primary key rewrite the target of AshAdmin's row-action links.

The Table, DataTable, and Show components built row-action URLs by raw string interpolation, splicing the primary key (and table, domain, and resource names) into the query string without URL-encoding. Ash resources routinely use user-settable string primary keys (slugs, emails). Because Plug.Conn.Query resolves duplicate parameters last-wins and primary_key is interpolated last, a stored key such as foo&action_type=destroy injects parameters that override the link, so an admin clicking edit is sent to a destroy form or an arbitrary resource; a # truncates the query into a fragment. The fix builds every link with URI.encode_query/1, encoding all interpolated values.

This issue affects ash_admin: from 0.3.0-rc.0 before 1.3.1.

## Patch verfügbar (OSV)

- 91da87c1c23cd6199ba1b0a1c8849a4c605130cc (Commit)
- 8e8ef91e8ba07498053887c6212f8b0f08178df6 (Commit)

## Referenzen

- <https://cna.erlef.org/cves/CVE-2026-82681.html>
- <https://github.com/ash-project/ash_admin/commit/8e8ef91e8ba07498053887c6212f8b0f08178df6>
- <https://github.com/ash-project/ash_admin/security/advisories/GHSA-j89q-xjrh-c26p>
- <https://osv.dev/vulnerability/EEF-CVE-2026-82681>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-82681) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
