CVE-2026-22599Disclosure(strapi / strapi)

MEDIUMCVSS 7.2 · HIGH

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch strapi strapi systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Strapi is an open source headless content management system. In versions on the 4.x branch prior to 4.26.1 and on the 5.x branch prior to 5.33.2, a database-query injection vulnerability existed in the Strapi Content-Type Builder write API. An authenticated administrator could inject arbitrary database statements through the `column.defaultTo` attribute when creating or modifying a content type. Setting `defaultTo` as a tuple `[value, { isRaw: true }]` caused the value to be passed directly into Knex's `db.connection.raw()` during schema migration without sanitization, allowing arbitrary statement execution at the database layer. Depending on the database engine, this enabled arbitrary file read via database utility functions, denial of service via forced server crash on schema-migration error, and on engines that permit external program execution, remote code execution against the database server. The patch in versions 4.26.1 and 5.33.2 addresses this by restricting all Content-Type Builder write APIs to development mode only. Production deployments running v5.33.2 or later return 404 for requests against `/content-type-builder/content-types` and related endpoints, removing the network-reachable attack surface entirely.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • strapi

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 7 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 7 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 3 mentions (2026-05-13); latest day: 2
  • 7 total mentions across 4 days

Affected systems

Vendors
Products
strapi

Deep dive

Activity timeline7 mentions / 4d
01223Mentions · 2026-05-13: 3Mentions · 2026-05-18: 1Mentions · 2026-06-02: 1Mentions · 2026-09-28: 2PoC Mentioned / Linked · 2026-09-28: 2Exploit Tool / Code · 2026-09-28: 2Patch / Workaround · 2026-05-13: 2Patch / Workaround · 2026-05-18: 1Patch / Workaround · 2026-09-28: 1Technical Details · 2026-05-13: 3Technical Details · 2026-05-18: 1Technical Details · 2026-06-02: 1Technical Details · 2026-09-28: 205-1305-1806-0209-28
Signal classification5 categories
Disclosure
228.6%
Patch
228.6%
General
114.3%
Exploit
114.3%
PoC
114.3%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-05-133
Disclosure2Patch1
2026-05-181
Patch1
2026-06-021
General1
2026-09-282
Exploit1PoC1
Full discourse7 posts
  • Gray Hats@the_yellow_fall
    Patch

    Two critical flaws in Strapi CMS (CVE-2026-27886 & CVE-2026-22599) allow unauthenticated admin takeover and SQL injection. Update your nodes now! #Strapi #CMS #CyberSecurity #InfoSec #RCE #VulnerabilityAlert #CVE #AdminTakeover #PatchNow #TechNews https://securityonline.info/strapi-cms-vulnerabilities-cve-2026-27886-cve-2026-22599-admin-takeover-rce/ https://t.co/jzNBfMzoH4

    Post summary

    Strapi CMS suffers from two critical flaws (CVE-2026-27886 & CVE-2026-22599) that allow unauthenticated admin takeover and SQL injection; users are urged to update their nodes promptly.

    030113634
    12.5K followersView on X
  • abraxas@abraxas_null
    Exploit

    A fun little one ;) Strapi CVE-2026-22599 - Critical 9.3 - Authenticated SQL Injection (Knex raw defaultTo) https://github.com/abraxas/CVE-2026-22599

    Post summary

    The tweet shares a GitHub repository for CVE-2026-22599, an authenticated SQL injection in Strapi rated CVSS 9.3, implying the availability of exploit code.

    01074377
    280 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 High - Strapi Content-Type Builder SQL Injection (CVE-2026-22599) A critical SQL injection in Strapi's Content-Type Builder lets an authenticated admin inject arbitrary SQL via the column.defaultTo attribute when creating or modifying content types, bypassing input sanitization through Knex's raw query path. Leads to data exfiltration, DoS, and potential RCE depending on DB engine (CVSS 9.3). 👉 Affected: @strapi/content-type-builder ≥ 5.0.0 < 5.33.2 and @strapi/plugin-content-type-builder ≥ 4.0.0 < 4.26.1 | Upgrade to 5.33.2 / 4.26.1

    Post summary

    A high‑severity SQL injection in Strapi's Content-Type Builder lets authenticated admins inject arbitrary SQL via the column.defaultTo attribute, potentially causing data exfiltration, DoS, or RCE. The fix is to upgrade to the latest package versions.

    00131350
    255 followersView on X
  • dbugs@ptdbugs
    PoC

    A PoC/exploit has been discovered for vulnerability CVE-2026-22599 PT ID: PT-2026-40834 Vendor: Strapi Product: Strapi Description: Strapi is an open source headless content management system. In versions on the 4.x branch prior to 4.26.1 and on the 5.x branch prior to 5.33.2, a database-query injection vulnerability existed in the Strapi Content-Type Builder write API. An authenticated administrator could inject arbitrary database statements through the "column.defaultTo" attribute when creating or modifying a content type. Setting "defaultTo" as a tuple "[value, { isRaw: true }]" caused the value to be passed directly into Knex's "db.connection.raw()" during schema migration without sanitization, allowing arbitrary statement execution at the database layer. Depending on the database engine, this enabled arbitrary file read via database utility functions, denial of service via forced server crash on schema-migration error, and on engines that permit external program execution, remote code execution against the database server. The patch in versions 4.26.1 and 5.33.2 addresses this by restricting all Content-Type Builder write APIs to development mode only. Production deployments running v5.33.2 or later return 404 for requests against "/content-type-builder/content-types" and related endpoints, removing the network-reachable attack surface entirely. References: • https://dbu.gs/vulnerability/PT-2026-40834 • https://github.com/abraxas/cve-2026-22599

    Post summary

    A Proof of Concept/exploit has been discovered for CVE-2026-22599 in Strapi's Content-Type Builder write API, enabling authenticated administrator database query injection via the 'column.defaultTo' attribute; patched versions 4.26.1 and 5.33.2 restrict the API to development mode and return 404 on production endpoints.

    10000498
    3.6K followersView on X
  • AI Heartland@peaks2314
    Patch

    ⚠️ Strapi使ってるなら今すぐバージョン確認を。 人気ヘッドレスCMS「Strapi」のContent-Type BuilderにCVSS 9.3のSQLインジェクション(CVE-2026-22599)。 管理画面でカラム作成時に指定する「デフォルト値(column.defaultTo)」が、内部のKnex.jsで生SQLとして処理され、サニタイズを素通りする。 結果はDB全件抜き取り・サービス停止・最悪RCEまで届く射程。「認証済み管理者」が条件だが、Strapiは管理者を複数人で共有する運用が多く、1アカウント乗っ取られた瞬間に詰む。 対応: ・@strapi/content-type-builder → 5.33.2へ ・plugin-content-type-builder(v4系)→ 4.26.1へ 管理画面を社外公開している場合は特に最優先で npm update。

    Post summary

    The tweet alerts users to a critical SQL injection in Strapi’s Content‑Type Builder and urges immediate update to the patched plugin versions, but does not provide a PoC or report active exploitation.

    00010186
    2.7K followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-22599: Strapi Content Type Builder SQL Injection - What It Means for Your Business and How to Respond https://hubs.li/Q04jN44Y0

    Post summary

    The tweet references a Strapi SQL Injection CVE but provides no PoC, exploit code, active exploitation claim, or patch details—just an introductory mention of its business impact.

    0000040
    32 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 Strapi, Database Query Injection, #CVE-2026-22599 (Critical) https://dailycve.com/strapi-database-query-injection-cve-2026-22599-critical/

    Post summary

    The content announces a critical database query injection vulnerability in Strapi identified as CVE-2026-22599.

    0000050
    202 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appstrapistrapi-node.js-

Explore more