CVE-2026-46645 is an authorization bypass vulnerability in SQLAdmin, a flexible admin interface for SQLAlchemy models. In versions prior to 0.25.1, the ajax_lookup endpoint in application.py does not enforce the same is_accessible() access-control check that other endpoints apply. In deployments where developers restrict access to specific models by overriding is_accessible(), an authenticated user can still send requests to ajax_lookup and query data from those otherwise restricted models. The flaw results from inconsistent authorization enforcement on this endpoint. The issue is fixed in SQLAdmin 0.25.1, which enforces is_accessible(request) and returns HTTP 403 when access is denied.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a local Docker lab and Python PoC for CVE-2026-46645, an authorization bypass in SQLAdmin's ajax_lookup endpoint. The exploit capability is limited but real: it authenticates as a low-privileged user, then directly requests /admin/report/ajax/lookup for a restricted ModelView whose is_accessible(request) returns False. In the vulnerable configuration (SQLAdmin 0.25.0), the endpoint still returns JSON lookup results for related SecretProject objects, exposing restricted data. In the patched configuration (0.25.1), the same request returns HTTP 403. Repository structure is straightforward: app/main.py contains the Starlette lab application, SQLAlchemy models, SQLAdmin setup, authentication backend, seeded demo data, and the intentionally restricted ReportAdmin view with form_ajax_refs configured on the project relationship. poc/poc.py is the main exploit entry point; it logs in to /admin/login using hardcoded lab credentials (analyst / lab-password), stores the session cookie, and sends a GET request to /admin/report/ajax/lookup with parameters name=project and term=Secret, then interprets the response as vulnerable (200 + JSON results) or patched (403). docker-compose.yml orchestrates two containers: vuln on host port 8001 using sqladmin==0.25.0 and patched on host port 8002 using sqladmin==0.25.1. The Dockerfiles and requirements files simply build these comparison environments. This is not malware or a destructive exploit; it is an operational PoC for authenticated information disclosure via authorization bypass in a web admin interface. It does not provide code execution, persistence, or lateral movement. The primary attack vector is web-based, and the main observable targets are the SQLAdmin login endpoint and the ajax_lookup route under /admin/report/ajax/lookup.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.