Strapi <=5.36.x - Admin Credential Enumeration
CVE-2026-27886
Verified
Description
Strapi versions starting in 4.0.0 and prior to 5.37.0 did not sufficiently sanitize query parameters when filtering content via relational fields. An attacker could use the `where` query parameter on any publicly-accessible content-type with an `updatedBy` field to perform a boolean-oracle attack against private fields on the joined admin_users table, including the resetPasswordToken field, enabling full administrative account takeover without authentication.
Severity
Critical
CVSS Score
9.2
Exploit Probability
3%
Affected Product
strapi
Published Date
September 22, 2026
Template Author
zeroc00i
CVE-2026-27886.yaml
9.2Score
CVSS Metrics
CVSS Vector:
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
CVE ID:
cve-2026-27886
CWE ID:
cwe-200
Remediation Steps
Upgrade Strapi to version 5.37.0 or later. The patch introduces explicit query-parameter sanitization via strictParam, addQueryParams, and addBodyParams primitives that reject operator chains traversing into restricted relational targets before reaching the database.