Vulnerability Description
SQLAdmin is a flexible Admin interface for SQLAlchemy models. Prior to version 0.25.1, the ajax_lookup endpoint in application.py bypasses the is_accessible() access control check that all other endpoints enforce. If a developer restricts model access by overriding is_accessible(), an authenticated user can still query that model's data through the ajax_lookup endpoint — silently bypassing the restriction. This issue has been patched in version 0.25.1.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/smithyhq/sqladmin/commit/b0d3a19fb9b074a9ed243de46930108375df
- https://github.com/smithyhq/sqladmin/pull/1035
- https://github.com/smithyhq/sqladmin/releases/tag/0.25.1
- https://github.com/smithyhq/sqladmin/security/advisories/GHSA-54mc-gghv-4cfj
FAQ
What is CVE-2026-46645?
CVE-2026-46645 is a vulnerability with a CVSS score of 4.3 (MEDIUM). SQLAdmin is a flexible Admin interface for SQLAlchemy models. Prior to version 0.25.1, the ajax_lookup endpoint in application.py bypasses the is_accessible() access control check that all other endpo...
How severe is CVE-2026-46645?
CVE-2026-46645 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-46645?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.