/Vulnerability Library

Strapi <=5.36.x - Admin Credential Enumeration

CVE-2026-27886
Verified

Description

Strapi versions starting in 4.0.0 and prior to 5.37.0 did not sufficiently sanitize query parameters when filtering content via relational fields. An attacker could use the `where` query parameter on any publicly-accessible content-type with an `updatedBy` field to perform a boolean-oracle attack against private fields on the joined admin_users table, including the resetPasswordToken field, enabling full administrative account takeover without authentication.

Severity

Critical

CVSS Score

9.2

Exploit Probability

3%

Affected Product

strapi

Published Date

September 22, 2026

Template Author

zeroc00i

CVE-2026-27886.yaml
9.2Score

CVSS Metrics

CVSS Vector:
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
CVE ID:
cve-2026-27886
CWE ID:
cwe-200

References

https://github.com/strapi/strapi/security/advisorieshttps://bishopfox.com/blog/cve-2026-27886-unauthenticated-boolean-oracle-exfiltration-of-administrator-secrets-in-strapihttps://github.com/BishopFox/CVE-2026-27886-checkhttps://nvd.nist.gov/vuln/detail/CVE-2026-27886

Remediation Steps

Upgrade Strapi to version 5.37.0 or later. The patch introduces explicit query-parameter sanitization via strictParam, addQueryParams, and addBodyParams primitives that reject operator chains traversing into restricted relational targets before reaching the database.