Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-89267— starlette-admin 0.16.1 through 0.17.1 Searchable Fields Allowlist Bypass

Quick assessment

Affected
jowilf starlette-admin
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

漏洞描述翻译: starlette-admin 版本 0.16.1 至 0.17.1 在将 配置为空列表时,未能强制应用该白名单机制,导致已认证用户能够对不可搜索的字段进行过滤操作。攻击者可以通过列表 API 的 参数提交结构化的过滤查询,从而对被排除的列执行等值及比较运算。

CVSS 4.3 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-89267

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
starlette-admin 0.16.1 through 0.17.1 Searchable Fields Allowlist Bypass
Source: CVE Program / CVE List V5
Vulnerability Description
starlette-admin versions 0.16.1 through 0.17.1 fail to enforce the searchable_fields allowlist when configured as an empty list, allowing authenticated users to filter on non-searchable fields. Attackers can submit structured filter queries via the list API's where parameter to perform equality and comparison operations on excluded columns.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制不正确
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
jowilf starlette-admin 0.16.1 ~ 0.17.1 -

II. Public POCs for CVE-2026-89267

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-89267

登录查看更多情报信息。

Other References for CVE-2026-89267 (3)

IV. Related Vulnerabilities

V. Comments for CVE-2026-89267

No comments yet


Leave a comment