THREAT OPS › Threat News › [NVD] CVE-2026-78038 — Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash_oban allows a user whose input reaches the :args option of AshOban.build_trigger/3 to retarget an update or destroy trigger at another record, including across tenants.
[NVD] CVE-2026-78038 — Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash_oban allows a user whose input reaches the :args option of AshOban.build_trigger/3 to retarget an update or destroy trigger at another record, including across tenants.
CVE-2026-78038 CVSS: None Published: 2026-08-30T12:17:18.157
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash_oban allows a user whose input reaches the :args option of AshOban.build_trigger/3 to retarget an update or destroy trigger at another record, including across tenants.
build_trigger/3 builds the trusted job arguments with a
Indicators of compromise
- CVE-2026-78038cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-78038