Cyber & AI intelligence
Wasteland.
Briefs indexed3090
Issues31
Published Mondays07:30 CT
⚡ Active KEV CVE-2023-22894 2026-10-08

Strapi CVE-2023-22894 Added to CISA KEV: Admin Query Filter Leaks Password Hashes and Reset Tokens

"CISA has added CVE-2023-22894, a Strapi flaw that lets an attacker with admin panel access pull sensitive user data through the query filter, to its Known Exploited Vulnerabilities catalog and set a remediation due date…"

CISA has added CVE-2023-22894, a Strapi flaw that lets an attacker with admin panel access pull sensitive user data through the query filter, to its Known Exploited Vulnerabilities catalog and set a remediation due date of October 11, 2026.

What Is It

CVE-2023-22894 is a cleartext storage of sensitive information flaw (CWE-312) in the Strapi content management platform. An attacker who can reach the admin panel can filter users by columns that hold sensitive data and work out the values from API responses.

How much is exposed depends on the attacker's access:

Why It Matters

CISA added the flaw to KEV on 2026-10-08, which confirms active exploitation. The CISA Coordinator SSVC assessment lists exploitation as "active," automatable as "no," and technical impact as "total."

CISA also says the flaw can be chained with CVE-2023-22621 to achieve remote code execution. That makes it more serious than its standalone score suggests. The entry is flagged for forensic triage. Use in ransomware campaigns is listed as "Unknown."

The two CVSS 3.1 scores differ: - NVD (Primary): 4.9 MEDIUM, CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N - CISA ADP (Secondary): 7.2 HIGH, CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Both scores require high privileges, so the main risk is to deployments where admin credentials are already compromised or the admin panel is exposed.

What's Vulnerable

CISA notes that affected products may be end-of-life or end-of-service. It also says the flaw may affect open-source components or other products that build on the same code.

Patch Status

CISA's required action is to apply mitigations according to vendor instructions, following BOD 26-04 (Prioritizing Security Updates Based on Risk) and CISA's Forensics Triage Requirements. Where mitigations aren't available, organizations should follow BOD 26-04 guidance for cloud services or stop using the product. Stakeholders must assess each asset's internet exposure.

Sources