logo

Critical Strapi Flaws Enable Unauthenticated Admin Takeover and Server RCE

ID: 75dde247-9d92-5261-8de9-c4a2443ae4e9

STIX ID: report--75dde247-9d92-5261-8de9-c4a2443ae4e9

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-05-18

Date Updated: 2026-05-18

Author: Ddos

...
...

A pair of critical vulnerabilities in the Strapi headless CMS (CVE-2026-22599 and CVE-2026-27886) allow attackers to inject arbitrary database statements via the Content-Type Builder and to perform an unauthenticated relational-query oracle attack to recover admin reset tokens and take over administrator accounts; fixes and behavioral IOCs have been published and administrators are urged to audit logs and update to patched versions (v5.33.2+ mitigations for the builder and v5.37.0+ for the relational-query fix).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.