THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-89267 (MEDIUM 4.3) — starlette-admin versions 0.16.1 through 0.17.1 fail to enforce the searchable_fields allowlist when configured as an empty list, allowing authenticated users to filter on non-searchable fields. Attackers can submit structured filter queries via the list API's where parameter to p

[NVD] CVE-2026-89267 (MEDIUM 4.3) — starlette-admin versions 0.16.1 through 0.17.1 fail to enforce the searchable_fields allowlist when configured as an empty list, allowing authenticated users to filter on non-searchable fields. Attackers can submit structured filter queries via the list API's where parameter to p

mednvdPublished 2026-09-12

CVE-2026-89267 CVSS: 4.3 MEDIUM Published: 2026-09-12T02:16:23.580

starlette-admin versions 0.16.1 through 0.17.1 fail to enforce the searchable_fields allowlist when configured as an empty list, allowing authenticated users to filter on non-searchable fields. Attackers can submit structured filter queries via the list API's where parameter to perform equality and comparison operations on exclude

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-89267