CVE-2026-27886 is an improper query-parameter sanitization vulnerability in Strapi versions 4.0.0 through 5.36.1. The Content API accepted an undocumented top-level where parameter and forwarded it into database query construction. A filter traversing a creator or other administrator relation caused query generation to join the administrator-user table and evaluate predicates against fields the unauthenticated caller was not authorized to read. Response-count differences exposed a boolean oracle, permitting character-by-character inference of private administrator fields, including password-reset tokens. Version 5.37.0 rejects query operator chains that traverse into restricted relational targets before database execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
find access to Content API collection types, or restrict public access to endpoints whose records contain creator or administrator relations. Monitor for anomalous relational filtering attempts targeting administrator-linked fields, repeated prefix-style probes, and unexpected administrator password-reset activity. Review administrative accounts and sessions after suspected exposure.Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository is a small, focused exploit project containing a README and one Python script, cve-2026-27886-exploit.py. The Python file is the main entry point and implements an automated end-to-end account takeover chain against vulnerable Strapi instances. It is not tied to a common exploitation framework. The exploit logic uses urllib-based HTTP GET and POST requests with a custom User-Agent string (cve-2026-27886-exploit/1.0). The workflow shown in the README and visible in the code is: (1) verify vulnerability by comparing baseline collection counts against a crafted filter query using where[id][$lt]=-1; (2) enumerate an admin email address using a boolean oracle based on where[updatedBy][email][$startsWith]; (3) trigger Strapi's password reset flow for the recovered email; (4) exfiltrate a 40-character hexadecimal reset token through repeated oracle requests; and (5) submit a new password and capture the returned JWT, yielding administrative access. Repository structure is minimal: README.md documents usage, examples, expected output, and operational notes; cve-2026-27886-exploit.py contains the exploit implementation, argument parsing, vulnerability verification mode, and full exploitation mode. The script supports optional known-email input to skip enumeration, configurable delay to evade rate limits, explicit base URL selection for admin endpoints, and a verify-only mode for safer testing. Operationally, this is more than a detector: it performs real account takeover and returns a usable JWT. The payload is basic and hardcoded by default via a new password value, making the exploit operational rather than merely a proof of concept. The README also notes the attack is noisy, requiring hundreds of requests for email and token extraction.
This repository contains a small, focused Strapi exploit PoC for CVE-2026-27886 plus a companion Nuclei detection template and README. The main exploit is the Python script CVE-2026-27886.py, which uses requests to query a user-supplied Strapi Content API collection endpoint. It first performs a differential check by comparing the normal collection total against a crafted request using where[id][$lt]=-1. If the baseline contains records and the false predicate collapses the result set to zero, the script treats the endpoint as vulnerable. The exploit capability goes beyond simple detection: with --enum-fields enabled, it abuses relational filtering and a startsWith oracle to enumerate related object fields character-by-character. Defaults indicate likely exfiltration of updatedBy.email values, though relations and fields are configurable. This makes it an operational data-exfiltration PoC rather than a pure detector. The script supports proxying, TLS verification control, configurable alphabet/max length/delay, and parses Strapi-style JSON responses by inspecting meta.pagination.total. The YAML file is a Nuclei template that only performs the two-request differential check and is therefore detection-focused, while the Python file is the actual exploit. Overall, the repository targets publicly accessible Strapi Content API endpoints vulnerable to query sanitization bypass in relational where filters, enabling unauthorized inference or extraction of sensitive related data.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical unauthenticated credential enumeration vulnerability in Strapi <=5.36.x that allows pre-auth disclosure of admin email addresses and reset password tokens.
A critical unauthenticated parameter sanitization bypass in Strapi Content API that allows attackers to leak administrator email and password-reset tokens via a boolean oracle and then take over admin accounts, including Super Admin, through the normal password reset flow.
An authentication bypass/account takeover vulnerability in Strapi caused by insufficient sanitization of relational query parameters, allowing an unauthenticated attacker to use a boolean-oracle technique to extract sensitive admin fields such as reset tokens and take over administrative accounts.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.