Sceawere
Vulnerability Detail
CVE-2026-108114UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Strapi Improper Authorization Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.3
- Creation Date
- 3h ago
- Vendor
- strapi
- Product
- strapi
- Attack Type
- Incorrect Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Strapi 5.47.0 through 5.57.0 contains an improper authorization vulnerability that allows admin API tokens to retain all-field Content Manager access after the owner's role is field-restricted. Because reconcileTokenPermissionsToUserCeiling ignores token permissions with omitted or null fields, token holders can keep reading content fields an administrator removed from the role.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.3",
"pubDate": "2026-10-10T15:16:56.213Z",
"pubdate": "2026-10-10T15:16:56.213Z",
"executiveSummary": "Strapi versions 5.47.0 through 5.57.0 are affected by an improper authorization vulnerability within the Content Manager API. The flaw stems from the inadequate synchronization of administrative API token permissions when a user's underlying role is restricted.\nSpecifically, the mechanism responsible for reconciling token permissions fails to correctly enforce field-level restrictions if the permission set contains omitted or null field values. Consequently, an existing API token retains full access to content fields that an administrator intended to revoke via role updates.\nThis vulnerability allows an attacker possessing a previously issued API token to bypass administrative access controls and continue accessing sensitive data that should be restricted. The risk is significant, as it effectively nullifies the 'principle of least privilege' for API tokens once field-level security configurations are modified. The vulnerability does not require the attacker to compromise new credentials, as it leverages pre-existing, authorized tokens that are no longer correctly constrained by the system's updated security policy.",
"technicalDetails": "The root cause of this vulnerability lies in the logic of the reconcileTokenPermissionsToUserCeiling function. This function is tasked with updating or auditing API token permissions to ensure they do not exceed the privileges defined by the owner's assigned role (the 'user ceiling').\nDuring the reconciliation process, the logic fails to explicitly handle cases where fields are explicitly omitted or nullified in the token permission set. Instead of strictly enforcing the updated role's field restrictions, the function skips the enforcement logic when it encounters these null or omitted states. This results in the system failing to prune or override the existing permission grant, thereby allowing the API token to retain its original, broader access scope.\nThe attack flow follows a predictable sequence: First, an administrator creates an API token for a specific user role that initially permits access to a set of content fields. Second, the administrator identifies a security requirement to restrict this role, specifically removing access to sensitive fields within the Content Manager. Third, the administrator updates the role, expecting that the API token reconciliation process will propagate these changes to existing tokens. Finally, due to the logic flaw in reconcileTokenPermissionsToUserCeiling, the token remains unaffected, continuing to return the restricted fields in API responses.\nAn attacker possessing such a token does not need to perform additional authentication or elevation; they simply continue to interact with the Strapi API as they would normally. The affected component is the internal API authorization service, specifically the logic governing the sync between role-based access control (RBAC) and administrative token permission objects. This vulnerability impacts all Strapi deployments running versions 5.47.0 to 5.57.0 that utilize API tokens for programmatic access to the Content Manager. Because the check occurs at the API level, the exposure is essentially local to the application's network interface, and successful exploitation grants unauthorized read access to fields that were intended to be protected by administrative policy."
}