CVE-2026-27886: Unauthenticated Boolean-Oracle Exfiltration of Administrator Secrets in Strapi
bishopfox.com | vulnerability | High | CVE-2026-27886 | #vulnerability-research | #access-control | #account-takeover | #information-disclosure | #strapi | #cve-2026-27886 | #oracle-attack | #sanitization-bypass
Summary
CVE-2026-27886 is a Strapi 4.0.0–5.36.1 sanitization bypass that turns API responses into a one-bit oracle; attackers extract an admin's reset token character by character, then take over the account.
- CVSS
- 7.5
- Published
- Collected
Skip to content