EEF A.I CyberSecurity Scoring
EEF
Company Information
Website:https://erlef.org
Employees number:20
Number of followers:1,935
NAICS:5112
Industry Type:Software Development
Homepage:erlef.org
EEF Risk Score (AI oriented)
Between 700 and 749
EEFSoftware Development
Updated:
31/08/2026
31/08/2026
748/1000
Moderate
Ba
EEF Global Score (TPRM)
xxxx
EEFSoftware Development
Score locked

EEFModerate
Current Score
748Ba (MODERATE)
01000
1 incidents
-2 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
748
AUGUST 2026
750
Vulnerability
30 Aug 2026 • EEF
Erlang Ecosystem Foundation: AshSqlite Vulnerability (CVE-2026-77846) Exposes Hidden JSON Fields
Critical AshSqlite Vulnerability (CVE-2026-77846) Exposes Hidden JSON Data in Database Queries
748
CRITICAL-2
ERL1788171832
Critical AshSqlite Vulnerability (CVE-2026-77846) Exposes Hidden JSON Data in Database Queries
On August 30, 2026, the Erlang Ecosystem Foundation’s CNA disclosed CVE-2026-77846, a JSONPath injection vulnerability in AshSqlite, a SQLite integration layer for the Ash Framework. The flaw allows attackers to traverse nested JSON structures and access sensitive or hidden fields in database records by manipulating untrusted input in field-selection requests.
### Key Details
- Affected Versions: AshSqlite 0.1.2-rc.0 through 0.2.17 (patched in 0.2.18).
- Root Cause: Unsafe construction of JSON paths, where attacker-controlled input (e.g., dots, brackets, or JSONPath symbols) could alter path interpretation, exposing nested data unintended for public access.
- Exploitation Vector: Attackers exploit the flaw via public APIs, search filters, or field-selection endpoints that accept untrusted input. A proof-of-concept (PoC) demonstrated how a single malicious path segment could leak nested values (e.g., `{"private": {"secret": "api-key"}}`).
- Impact: Systems processing untrusted input (e.g., public-facing applications) are at higher risk, while internal applications with trusted callers face lower exposure. The vulnerability does not involve SQL injection but abuses SQLite’s JSON path handling.
### Mitigation & Fixes
- Patch: Upgrade to AshSqlite 0.2.18 or later, which replaces unsafe path joining with secure encoding, escaping backslashes/quotes, and separate handling of numeric array indexes.
- Temporary Workarounds: Restrict dynamic field-selection input, audit logs for unusual JSONPath characters (e.g., dots, brackets), and review dependency locks for older versions.
- Detection: Monitor for malformed input (e.g., unbalanced brackets) or SQLite JSON path errors, which may indicate exploitation attempts.
The vulnerability underscores the risks of improper input validation in JSON path processing, particularly in applications handling sensitive data. Organizations using AshSqlite should prioritize upgrades and audits of affected systems.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
JULY 2026
750
JUNE 2026
750
MAY 2026
750
APRIL 2026
750
MARCH 2026
750
FEBRUARY 2026
750
JANUARY 2026
750
DECEMBER 2025
750
NOVEMBER 2025
750
OCTOBER 2025
750
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for EEF ??
What was EEF's A.I Rankiteo Cyber Score in August 2026 ??
What was EEF's A.I Rankiteo Cyber Score in July 2026 ??
What was EEF's A.I Rankiteo Cyber Score in June 2026 ??
What was EEF's A.I Rankiteo Cyber Score in May 2026 ??
What was EEF's A.I Rankiteo Cyber Score in April 2026 ??
What was EEF's A.I Rankiteo Cyber Score in March 2026 ??
What was EEF's A.I Rankiteo Cyber Score in February 2026 ??
What was EEF's A.I Rankiteo Cyber Score in January 2026 ??
What was EEF's A.I Rankiteo Cyber Score in December 2025 ??
What was EEF's A.I Rankiteo Cyber Score in November 2025 ??
What was EEF's A.I Rankiteo Cyber Score in October 2025 ??
What is the average per-incident point impact on EEF's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with EEF ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view EEF's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?