SB2026042378 - Improper access control in strapi



SB2026042378 - Improper access control in strapi

Published: April 23, 2026

Security Bulletin ID SB2026042378
CSH Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Improper access control (CVE-ID: CVE-2024-56143)

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper access control in the parms.lookup query operator when processing lookup filter parameters for private fields. A remote attacker can send a specially crafted lookup query to disclose sensitive information.

The issue can be used to perform filtering attacks against private fields, including admin passwords and reset tokens.


Remediation

Install update from vendor's website.