MEDIUMVulnerability
CVE-2026-89267
starlette-admin versions 0.16.1 through 0.17.1 fail to enforce the searchable_fields allowlist when configured as an empty list, allowing authenticated users to filter on non-searchable fields. Attackers can submit structured filter queries via the list API's where parameter to perform equality and comparison operations on excluded columns.
Properties
- severity
- MEDIUM
- score
- 4.3
- cve_id
- CVE-2026-89267
- signal_observed_at
- 2026-09-21T23:07:07+00:00
- vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- published_at
- 2026-09-12T02:16:23.580
- last_modified
- 2026-09-15T17:17:36.800
Related Entities (2)
HAS_WEAKNESS (1)
→[Weakness]Incorrect Authorization
DESCRIBED_BY (1)
→[Source]NVD
Explore deeper with Ninja Signal's threat intelligence graph