VDB
Sign up

EEF-CVE-2026-82724

Broken access control in AshPhoenix SubdomainHook via a nil tenant in handle_subdomain

Quick fix

EEF-CVE-2026-82724 — ash_phoenix: upgrade to the fixed version with the command below.

mix deps.update ash_phoenix

Details

## Summary

Incorrect Authorization vulnerability in ash-project ash\_phoenix invokes the SubdomainHook authorization callback with a nil tenant, so tenant-scoped access checks never see the tenant they are meant to enforce.

AshPhoenix.LiveView.SubdomainHook.on\_mount/4 attached a handle\_params hook to assign the tenant and then immediately called handle\_subdomain in the same on\_mount. The tenant assign is only written when LiveView later runs handle\_params, strictly after on\_mount returns, so handle\_subdomain read an unset assign and ran as apply(m, f, \[socket, nil | a\]). A consumer gate that halts when the user does not belong to the tenant instead evaluated nil, either crashing or taking a permissive branch, and it was never re-run once the real subdomain was assigned or on later navigations. The fix runs handle\_subdomain inside the handle\_params hook with the real tenant on every navigation.

This issue affects ash\_phoenix: from 2.1.26 before 2.3.25.

## Configuration

The application uses AshPhoenix.LiveView.SubdomainHook with a handle\_subdomain callback as a tenant-scoped authorization gate.

Are you affected?

Enter the version of the package you're using.

Affected packages

Hex/ash_phoenix
Introduced in: 2.1.26Fixed in: 2.3.25
Fixmix deps.update ash_phoenix

References