Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 15 Sep 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 13 Sep 2026 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jowilf
Jowilf starlette-admin |
|
| Vendors & Products |
Jowilf
Jowilf starlette-admin |
Sat, 12 Sep 2026 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | starlette-admin versions 0.16.1 through 0.17.1 fail to enforce the searchable_fields allowlist when configured as an empty list, allowing authenticated users to filter on non-searchable fields. Attackers can submit structured filter queries via the list API's where parameter to perform equality and comparison operations on excluded columns. | |
| Title | starlette-admin 0.16.1 through 0.17.1 Searchable Fields Allowlist Bypass | |
| First Time appeared |
Encode
Encode starlette |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:encode:starlette:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Encode
Encode starlette |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-15T16:57:01.333Z
Reserved: 2026-09-11T10:52:56.669Z
Link: CVE-2026-89267
Updated: 2026-09-15T16:56:56.773Z
Status : Received
Published: 2026-09-12T02:16:23.580
Modified: 2026-09-15T17:17:36.800
Link: CVE-2026-89267
No data.
OpenCVE Enrichment
Updated: 2026-09-15T03:30:14Z
-
CWE-863
Incorrect Authorization