CVE-2026-89267 - starlette-admin 0.16.1 through 0.17.1 Searchable Fields Allowlist Bypass
CVE ID :CVE-2026-89267
Published : Sept. 12, 2026, 2:16 a.m. | 2 hours, 50 minutes ago
Description :starlette-admin versions 0.16.1 through 0.17.1 fail to enforce the searchable_fields allowlist when configured as an empty list, allowing authenticated users to filter on non-searchable fields. Attackers can submit structured filter queries via the list API's where parameter to perform equality and comparison operations on excluded columns.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Sept. 12, 2026, 2:16 a.m. | 2 hours, 50 minutes ago
Description :starlette-admin versions 0.16.1 through 0.17.1 fail to enforce the searchable_fields allowlist when configured as an empty list, allowing authenticated users to filter on non-searchable fields. Attackers can submit structured filter queries via the list API's where parameter to perform equality and comparison operations on excluded columns.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...