PT-2026-90553 · Jowilf · Starlette-Admin

CVE-2026-89267

·

Published

2026-09-12

·

Updated

2026-09-12

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
starlette-admin versions 0.16.1 through 0.17.1 fail to enforce the searchable fields allowlist when configured as an empty list, allowing authenticated users to filter on non-searchable fields. Attackers can submit structured filter queries via the list API's where parameter to perform equality and comparison operations on excluded columns.

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-89267

Affected Products

Starlette-Admin