CISA has added CVE-2023-22894, a Strapi flaw that lets an attacker with admin panel access pull sensitive user data through the query filter, to its Known Exploited Vulnerabilities catalog and set a remediation due date of October 11, 2026.
What Is It
CVE-2023-22894 is a cleartext storage of sensitive information flaw (CWE-312) in the Strapi content management platform. An attacker who can reach the admin panel can filter users by columns that hold sensitive data and work out the values from API responses.
How much is exposed depends on the attacker's access:
- Super admin access: the attacker can recover the password hash and password reset token of every user.
- Lower-privileged admin access: an account allowed to see the username and email of lower-privileged API users (for example, Editor or Author) can expose sensitive information for all API users, but not for other admin accounts.
Why It Matters
CISA added the flaw to KEV on 2026-10-08, which confirms active exploitation. The CISA Coordinator SSVC assessment lists exploitation as "active," automatable as "no," and technical impact as "total."
CISA also says the flaw can be chained with CVE-2023-22621 to achieve remote code execution. That makes it more serious than its standalone score suggests. The entry is flagged for forensic triage. Use in ransomware campaigns is listed as "Unknown."
The two CVSS 3.1 scores differ:
- NVD (Primary): 4.9 MEDIUM, CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
- CISA ADP (Secondary): 7.2 HIGH, CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Both scores require high privileges, so the main risk is to deployments where admin credentials are already compromised or the admin panel is exposed.
What's Vulnerable
- Vendor/Product: Strapi / Strapi
- The CVE description lists Strapi through 4.5.5 as affected.
- NVD's configuration data marks versions from 3.2.1 up to, but not including, 4.8.0 as vulnerable (
cpe:2.3:a:strapi:strapi:*).
CISA notes that affected products may be end-of-life or end-of-service. It also says the flaw may affect open-source components or other products that build on the same code.
Patch Status
CISA's required action is to apply mitigations according to vendor instructions, following BOD 26-04 (Prioritizing Security Updates Based on Risk) and CISA's Forensics Triage Requirements. Where mitigations aren't available, organizations should follow BOD 26-04 guidance for cloud services or stop using the product. Stakeholders must assess each asset's internet exposure.
- Due date: 2026-10-11
- CISA advises users of end-of-life or end-of-service versions to stop using them or move to a supported version.
- Vendor guidance is in Strapi's security disclosure and its GitHub release notes.