Vulnerability Description
starlette-admin versions 0.16.1 through 0.17.1 fail to enforce the searchable_fields allowlist when configured as an empty list, allowing authenticated users to filter on non-searchable fields. Attackers can submit structured filter queries via the list API's where parameter to perform equality and comparison operations on excluded columns.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/jowilf/starlette-admin
- https://github.com/jowilf/starlette-admin/blob/0.17.1/starlette_admin/views.py#L
- https://www.vulncheck.com/advisories/starlette-admin-0.16.1-through-0.17.1-searc
FAQ
What is CVE-2026-89267?
CVE-2026-89267 is a vulnerability with a CVSS score of 4.3 (MEDIUM). starlette-admin versions 0.16.1 through 0.17.1 fail to enforce the searchable_fields allowlist when configured as an empty list, allowing authenticated users to filter on non-searchable fields. Attack...
How severe is CVE-2026-89267?
CVE-2026-89267 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-89267?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.