SB2026042378 - Improper access control in strapi
Published: April 23, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper access control (CVE-ID: CVE-2024-56143)
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in the parms.lookup query operator when processing lookup filter parameters for private fields. A remote attacker can send a specially crafted lookup query to disclose sensitive information.
The issue can be used to perform filtering attacks against private fields, including admin passwords and reset tokens.
Remediation
Install update from vendor's website.