THREAT OPS › Threat News › [NVD] CVE-2026-78699 — Unchecked Return Value vulnerability in ash-project ash_postgres allows a user who can drive a tenant rename to a name that collides with an existing tenant's schema to have their tenant record repointed at that other tenant's live schema, gaining access to its data.
AshPostgres
[NVD] CVE-2026-78699 — Unchecked Return Value vulnerability in ash-project ash_postgres allows a user who can drive a tenant rename to a name that collides with an existing tenant's schema to have their tenant record repointed at that other tenant's live schema, gaining access to its data. AshPostgres
CVE-2026-78699 CVSS: None Published: 2026-08-30T16:16:42.623
Unchecked Return Value vulnerability in ash-project ash_postgres allows a user who can drive a tenant rename to a name that collides with an existing tenant's schema to have their tenant record repointed at that other tenant's live schema, gaining access to its data.
AshPostgres.MultiTenancy.rename_tenant/3 issues the ALTER SCHEMA ...
Indicators of compromise
- CVE-2026-78699cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-78699