Strapi disclosed CVE-2026-27886, a critical query-sanitization bypass affecting @strapi/strapi versions 4.0.0 through 5.36.1 that allowed unauthenticated attackers to leak sensitive administrator data from public Content API endpoints. The flaw let crafted top-level and relational filter parameters such as where[updatedBy] reach the database layer, where response-count differences in meta.pagination.total created a boolean oracle against private fields in the joined admin_users table. Researchers said attackers could recover values including administrator email addresses and resetPasswordToken data one character at a time, provided the target exposed at least one publicly readable collection linked to an admin account through updated_by_id or created_by_id.
By combining the oracle with Strapi's unauthenticated /admin/forgot-password and /admin/reset-password flows, an attacker could recover a 40-character reset token and obtain a Super Admin JWT without user interaction, resulting in full administrative takeover. Strapi fixed the issue in 5.37.0 and described new sanitization controls that block unsafe query-parameter chains before execution, while Bishop Fox published technical details and a detection tool for identifying exposed instances. Defenders were advised to upgrade immediately, rotate administrator passwords, invalidate outstanding reset tokens, and review logs for indicators such as repeated where probes against admin-related fields, iterative hex-character guessing from a single IP, and unexpected password-reset activity.
See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
A GitHub pull request to ProjectDiscovery's nuclei-templates repository introduced a Nuclei template for CVE-2026-27886 that performs differential checks and brute-forces Strapi admin email and resetPasswordToken values character by character. The template was validated against a Strapi 5.36.1 lab instance and updated with corrected scoring and metadata.
Bishop Fox published technical analysis confirming that CVE-2026-27886 can be chained with Strapi's unauthenticated forgot-password and reset-password endpoints to recover an admin reset token and obtain a Super Admin JWT. The company also released a detection tool for identifying vulnerable instances without completing account takeover and advised password rotation and token invalidation.
Strapi publicly disclosed CVE-2026-27886 as a critical vulnerability with a CVSS score of 9.3, explaining that unauthenticated attackers could use public Content API endpoints as a boolean oracle to leak admin data and potentially take over accounts. The advisory also shared indicators of compromise and noted fixed versions were available.
Strapi remediated a critical query-parameter sanitization flaw affecting versions 4.0.0 through 5.36.1 by releasing version 5.37.0. The patch tightened query sanitization and blocked unsafe relational filtering paths that could expose administrator secrets.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcebishopfox.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.