THREAT OPS › Threat News › [NVD] CVE-2026-89267 (MEDIUM 4.3) — starlette-admin versions 0.16.1 through 0.17.1 fail to enforce the searchable_fields allowlist when configured as an empty list, allowing authenticated users to filter on non-searchable fields. Attackers can submit structured filter queries via the list API's where parameter to p
[NVD] CVE-2026-89267 (MEDIUM 4.3) — starlette-admin versions 0.16.1 through 0.17.1 fail to enforce the searchable_fields allowlist when configured as an empty list, allowing authenticated users to filter on non-searchable fields. Attackers can submit structured filter queries via the list API's where parameter to p
CVE-2026-89267 CVSS: 4.3 MEDIUM Published: 2026-09-12T02:16:23.580
starlette-admin versions 0.16.1 through 0.17.1 fail to enforce the searchable_fields allowlist when configured as an empty list, allowing authenticated users to filter on non-searchable fields. Attackers can submit structured filter queries via the list API's where parameter to perform equality and comparison operations on exclude
Indicators of compromise
- CVE-2026-89267cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-89267