Critical Strapi Flaws Enable Unauthenticated Admin Takeover and Server RCE
ID: 75dde247-9d92-5261-8de9-c4a2443ae4e9
STIX ID: report--75dde247-9d92-5261-8de9-c4a2443ae4e9
Feed Name: securityonline.info
A pair of critical vulnerabilities in the Strapi headless CMS (CVE-2026-22599 and CVE-2026-27886) allow attackers to inject arbitrary database statements via the Content-Type Builder and to perform an unauthenticated relational-query oracle attack to recover admin reset tokens and take over administrator accounts; fixes and behavioral IOCs have been published and administrators are urged to audit logs and update to patched versions (v5.33.2+ mitigations for the builder and v5.37.0+ for the relational-query fix).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
