Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

CVE-2026-27886: Unauthenticated Boolean-Oracle Exfiltration of Administrator Secrets in Strapi

Summary

CVE-2026-27886 is a Strapi 4.0.0–5.36.1 sanitization bypass that turns API responses into a one-bit oracle; attackers extract an admin's reset token character by character, then take over the account.
CVSS
7.5
Published
Collected

original ↗

Related coverage

back