CVE-2026-27886Disclosure(strapi / strapi)

LOWCVSS 7.5 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch strapi strapi systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Strapi is an open source headless content management system. Strapi versions starting in 4.0.0 and prior to 5.37.0 did not sufficiently sanitize query parameters when filtering content via relational fields. An unauthenticated attacker could use the `where` query parameter on any publicly-accessible content-type with an `updatedBy` (or other admin-relation) field to perform a boolean-oracle attack against private fields on the joined `admin_users` table, including the `resetPasswordToken` field. Extracting an admin reset token via this oracle made full administrative account takeover possible without authentication. When a filter such as `where[updatedBy][resetPasswordToken][$startsWith]=a` was applied to a public Content API endpoint, the underlying query generation performed a `LEFT JOIN` against the `admin_users` table and emitted a `WHERE` clause referencing the joined column. The query parameter sanitization layer did not block operator chains that traversed into relational target schemas the caller had no read permission on, allowing the response count to be used as a one-bit oracle on any admin-table field. The patch in version 5.37.0 introduces explicit query-parameter sanitization at the controller and service boundary via three new primitives: `strictParam`, `addQueryParams`, and `addBodyParams`. Operator chains that traverse into restricted relational targets are now rejected before reaching the database.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22CWE-200CWE-943

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • strapi

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 9 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 7 signals
  • Disclosure: 4 classified signals
  • General: 2 classified signals
  • Peaked 6d ago at 2 mentions (2026-05-14); latest day: 1
  • 9 total mentions across 7 days

Affected systems

Vendors
Products
strapi

Deep dive

Activity timeline9 mentions / 7d
01122Mentions · 2026-05-14: 2Mentions · 2026-05-18: 1Mentions · 2026-05-22: 1Mentions · 2026-05-27: 2Mentions · 2026-06-04: 1Mentions · 2026-09-22: 1Mentions · 2026-09-23: 1PoC Mentioned / Linked · 2026-09-23: 1Patch / Workaround · 2026-05-14: 1Patch / Workaround · 2026-05-18: 1Patch / Workaround · 2026-09-22: 1Technical Details · 2026-05-14: 2Technical Details · 2026-05-18: 1Technical Details · 2026-05-22: 1Technical Details · 2026-05-27: 1Technical Details · 2026-06-04: 1Technical Details · 2026-09-22: 105-1405-1805-2205-2706-0409-2209-23
Signal classification4 categories
Disclosure
444.4%
Patch
222.2%
General
222.2%
PoC
111.1%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-05-142
Disclosure2
2026-05-181
Patch1
2026-05-221
Disclosure1
2026-05-272
General2
2026-06-041
Disclosure1
2026-09-221
Patch1
2026-09-231
PoC1
Full discourse9 posts
  • Gray Hats@the_yellow_fall
    Patch

    Two critical flaws in Strapi CMS (CVE-2026-27886 & CVE-2026-22599) allow unauthenticated admin takeover and SQL injection. Update your nodes now! #Strapi #CMS #CyberSecurity #InfoSec #RCE #VulnerabilityAlert #CVE #AdminTakeover #PatchNow #TechNews https://securityonline.info/strapi-cms-vulnerabilities-cve-2026-27886-cve-2026-22599-admin-takeover-rce/ https://t.co/jzNBfMzoH4

    Post summary

    The tweet discloses two critical flaws in Strapi CMS that enable unauthenticated admin takeover and SQL injection, and urges users to update their nodes to remediate the issues.

    030113634
    12.5K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Patch

    🚨 CVE-2026-27886 - critical 🚨 Strapi <=5.36.x - Admin Credential Enumeration > Strapi versions starting in 4.0.0 and prior to 5.37.0 did not sufficiently sanitize q... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-27886 @pdnuclei #NucleiTemplates #cve

    Post summary

    The tweet reports that Strapi versions prior to 5.37.0 contain an admin credential enumeration vulnerability and indicates that version 5.37.0 (or later) patches the issue.

    02085468
    1.3K followersView on X
  • zeroc00i@zeroc00i
    PoC

    Grateful to give a little back to open source. My Strapi (CVE-2026-27886) detection template just landed in @pdnuclei's nuclei-templates. Open source keeps giving. https://github.com/projectdiscovery/nuclei-templates/pull/16304/changes/7247bac3eb5eb27cba9bc613a91abb8c9c697853 #nuclei #bugbounty #pentest https://t.co/5QzhGOE3xJ

    Post summary

    The tweet announces that a detection template for CVE-2026-27886 has been added to the Project Discovery Nuclei templates repository, providing a proof‑of‑concept for scanning the vulnerability.

    00070230
    544 followersView on X
  • Forgepoint Capital@forgepointcap
    Disclosure

    New research from @bishopfox details CVE-2026-27886, a critical vulnerability impacting Strapi instances that could allow unauthenticated attackers to extract administrator secrets and potentially gain full account takeover. Learn more: https://bishopfox.com/blog/cve-2026-27886-unauthenticated-boolean-oracle-exfiltration-of-administrator-secrets-in-strapi #forgepointfamily

    Post summary

    Bishop Fox announces a critical Strapi vulnerability, CVE‑2026‑27886, that lets unauthenticated attackers extract admin secrets and potentially hijack accounts.

    0001162
    885 followersView on X
  • DFIR Radar@DFIR_Radar
    Disclosure

    CVE-2026-27886 (CVSS pending) in Strapi 4.0.0-5.36.1 allows unauthenticated boolean-oracle attacks to extract admin password reset tokens character-by-character for account takeover. Over 20,000 internet-facing hosts affected. #DFIR_Radar https://t.co/txKYiEzuLO

    Post summary

    The tweet announces CVE‑2026‑27886, detailing a boolean‑oracle flaw that lets attackers harvest admin reset tokens from Strapi installations and notes over 20,000 affected hosts.

    10010162
    1.5K followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 Critical - Strapi Sensitive Data Exposure via Relational Filtering (CVE-2026-27886) Strapi contains a query sanitization flaw that allows unauthenticated attackers to abuse relational filtering on public Content API endpoints to leak sensitive admin data, including password reset tokens. Successful exploitation could lead to full administrative account takeover without authentication. 👉 Affected: @strapi/strapi >= 4.0.0 < 5.37.0 | Fix: Upgrade to 5.37.0

    Post summary

    The post announces a critical Strapi vulnerability (CVE‑2026‑27886) that allows unauthenticated attackers to exploit query sanitization flaws to extract admin data and potentially take over accounts, with a fix to upgrade to version 5.37.0.

    00020118
    255 followersView on X
  • Nate Robb@NateRobb
    General

    CVE-2026-27886 is another CVE we researched/reproduced as part of @bishopfox's Emerging Threat process. Full admin account takeover in Strapi, ~20k internet-facing instances via Shodan. Also, check out our detection tool: https://github.com/BishopFox/CVE-2026-27886-check

    Post summary

    The post announces research on CVE-2026-27886, noting its ability for full admin takeover in Strapi and identifying ~20k affected instances, and provides a detection tool, but offers no evidence of exploitation or PoC code.

    00010131
    198 followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-27886: Strapi Admin Account Takeover via Query Parameter Sanitization Bypass - What It Means for Your Business and How to Respond https://hubs.li/Q04h_NhZ0

    Post summary

    The provided text is merely a headline announcing the CVE without supplying evidence of exploitation, a PoC, patches, or technical depth.

    0000036
    31 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 Strapi, Boolean #Oracle Information Disclosure, #CVE-2026-27886 (Critical) https://dailycve.com/strapi-boolean-oracle-information-disclosure-cve-2026-27886-critical/

    Post summary

    The tweet announces a newly identified critical vulnerability (CVE‑2026‑27886) in Strapi, describing it as a Boolean Oracle information disclosure with no PoC, exploit, or patch details.

    0000056
    202 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appstrapistrapi-node.js-

Explore more