EEF-CVE-2026-82724
Broken access control in AshPhoenix SubdomainHook via a nil tenant in handle_subdomain
Quick fix
EEF-CVE-2026-82724 — ash_phoenix: upgrade to the fixed version with the command below.
mix deps.update ash_phoenixDetails
## Summary
Incorrect Authorization vulnerability in ash-project ash\_phoenix invokes the SubdomainHook authorization callback with a nil tenant, so tenant-scoped access checks never see the tenant they are meant to enforce.
AshPhoenix.LiveView.SubdomainHook.on\_mount/4 attached a handle\_params hook to assign the tenant and then immediately called handle\_subdomain in the same on\_mount. The tenant assign is only written when LiveView later runs handle\_params, strictly after on\_mount returns, so handle\_subdomain read an unset assign and ran as apply(m, f, \[socket, nil | a\]). A consumer gate that halts when the user does not belong to the tenant instead evaluated nil, either crashing or taking a permissive branch, and it was never re-run once the real subdomain was assigned or on later navigations. The fix runs handle\_subdomain inside the handle\_params hook with the real tenant on every navigation.
This issue affects ash\_phoenix: from 2.1.26 before 2.3.25.
## Configuration
The application uses AshPhoenix.LiveView.SubdomainHook with a handle\_subdomain callback as a tenant-scoped authorization gate.
Are you affected?
Enter the version of the package you're using.