Improper Input Validation in Starlette-Admin by Jowilf
CVE-2026-54553

5.4MEDIUM

Key Information:

Vendor

Jowilf

Vendor
CVE Published:
26 August 2026

What is CVE-2026-54553?

Starlette-Admin prior to version 0.16.1 contains an improper input validation vulnerability within its list API. This allows authenticated users to bypass restrictions by supplying arbitrary field names for sorting and filtering, potentially exposing sensitive information or causing unhandled exceptions. It can lead to HTTP 500 responses, which may result in denial of service for targeted requests. This issue has been addressed in version 0.16.1, enhancing the security controls of field validation.

Affected Version(s)

starlette-admin < 0.16.1

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.