starlette-admin versions 0.16.1 through 0.17.1 fail to enforce the searchable_fields allowlist when configured as an empty list, allowing authenticated users to filter on non-searchable fields. Attackers can submit structured filter queries via the list API's where parameter to perform equality and comparison operations on excluded columns.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 13 Sep 2026 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jowilf
Jowilf starlette-admin |
|
| Vendors & Products |
Jowilf
Jowilf starlette-admin |
Sat, 12 Sep 2026 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | starlette-admin versions 0.16.1 through 0.17.1 fail to enforce the searchable_fields allowlist when configured as an empty list, allowing authenticated users to filter on non-searchable fields. Attackers can submit structured filter queries via the list API's where parameter to perform equality and comparison operations on excluded columns. | |
| Title | starlette-admin 0.16.1 through 0.17.1 Searchable Fields Allowlist Bypass | |
| First Time appeared |
Encode
Encode starlette |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:encode:starlette:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Encode
Encode starlette |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-12T01:50:33.194Z
Reserved: 2026-09-11T10:52:56.669Z
Link: CVE-2026-89267
No data.
Status : Received
Published: 2026-09-12T02:16:23.580
Modified: 2026-09-12T02:16:23.580
Link: CVE-2026-89267
No data.
OpenCVE Enrichment
Updated: 2026-09-13T22:15:16Z
Weaknesses