Allowlist Bypass in starlette-admin Products by Jowilf
CVE-2026-89267
5.3MEDIUM
What is CVE-2026-89267?
The starlette-admin versions 0.16.1 through 0.17.1 contain a vulnerability that fails to enforce the searchable_fields allowlist correctly when this list is configured as empty. This oversight permits authenticated users to exploit the API by submitting structured filter queries. Attackers can manipulate the list API's where parameter to perform unauthorized equality and comparison operations on fields that should be excluded from search functionality. This vulnerability poses a risk by potentially revealing sensitive information that should remain protected.
Affected Version(s)
starlette-admin 0.16.1 <= 0.17.1
