Allowlist Bypass in starlette-admin Products by Jowilf
CVE-2026-89267

5.3MEDIUM

Key Information:

Vendor

Jowilf

Vendor
CVE Published:
12 September 2026

What is CVE-2026-89267?

The starlette-admin versions 0.16.1 through 0.17.1 contain a vulnerability that fails to enforce the searchable_fields allowlist correctly when this list is configured as empty. This oversight permits authenticated users to exploit the API by submitting structured filter queries. Attackers can manipulate the list API's where parameter to perform unauthorized equality and comparison operations on fields that should be excluded from search functionality. This vulnerability poses a risk by potentially revealing sensitive information that should remain protected.

Affected Version(s)

starlette-admin 0.16.1 <= 0.17.1

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Harsh Raj Singhania
.