THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-78699 — Unchecked Return Value vulnerability in ash-project ash_postgres allows a user who can drive a tenant rename to a name that collides with an existing tenant's schema to have their tenant record repointed at that other tenant's live schema, gaining access to its data. AshPostgres

[NVD] CVE-2026-78699 — Unchecked Return Value vulnerability in ash-project ash_postgres allows a user who can drive a tenant rename to a name that collides with an existing tenant's schema to have their tenant record repointed at that other tenant's live schema, gaining access to its data. AshPostgres

mednvdPublished 2026-08-30

CVE-2026-78699 CVSS: None Published: 2026-08-30T16:16:42.623

Unchecked Return Value vulnerability in ash-project ash_postgres allows a user who can drive a tenant rename to a name that collides with an existing tenant's schema to have their tenant record repointed at that other tenant's live schema, gaining access to its data.

AshPostgres.MultiTenancy.rename_tenant/3 issues the ALTER SCHEMA ...

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-78699