THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-78038 — Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash_oban allows a user whose input reaches the :args option of AshOban.build_trigger/3 to retarget an update or destroy trigger at another record, including across tenants.

[NVD] CVE-2026-78038 — Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash_oban allows a user whose input reaches the :args option of AshOban.build_trigger/3 to retarget an update or destroy trigger at another record, including across tenants.

mednvdPublished 2026-08-30

CVE-2026-78038 CVSS: None Published: 2026-08-30T12:17:18.157

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash_oban allows a user whose input reaches the :args option of AshOban.build_trigger/3 to retarget an update or destroy trigger at another record, including across tenants.

build_trigger/3 builds the trusted job arguments with a

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-78038