Strapi CVE-2023-22894 data exposure flaw added to CISA KEV catalog
At a glance
| Severity | HIGH |
|---|---|
| CVSS | CVE-2023-22894: 4.9 |
| EPSS (30-day exploit probability) | CVE-2023-22894: 1.7% |
| In CISA KEV (exploited) | Yes, due 2026-10-11 |
| Vendor | Strapi |
| CVE IDs | CVE-2023-22894 |
CISA added the Strapi vulnerability CVE-2023-22894 to its Known Exploited Vulnerabilities (KEV) catalog on 8 October 2026, which means it considers the flaw exploited in real attacks. US federal agencies have until 11 October 2026 to apply mitigations, and any team running Strapi should treat that as a signal to check its own exposure now.
The bug lets someone who already has access to the Strapi admin panel pull sensitive user data out of the system. Exploitation by attackers with no admin access is not described in the sources we reviewed.
What happened
CISA catalogued the issue as a cleartext storage of sensitive information vulnerability in Strapi, the open-source headless content management system. According to the NVD description, an attacker with admin panel access can abuse the query filter to filter users by columns that hold sensitive data, then infer the values from the API responses.
The impact depends on the account the attacker controls:
- With super admin access, the attacker can recover the password hash and password reset token of every user.
- With an admin account that can see the username and email of lower privileged API users (such as Editor or Author), the attacker can learn sensitive details of all API users, but not of other admin accounts.
CISA’s entry also notes that the flaw can be chained with CVE-2023-22621 to achieve remote code execution. Details of how that chain has been used in attacks have not been disclosed in the material we have.
Am I affected? Strapi versions at risk
The affected range listed in the vulnerability data is:
- Strapi versions from 3.2.1 up to, but not including, 4.8.0.
The NVD text says “through 4.5.5”, which is narrower than the 4.8.0 boundary in the affected-product data. The two sources conflict, so do not assume a 4.6 or 4.7 install is safe. Any version below 4.8.0 should be treated as affected until the vendor confirms otherwise.
CISA also warns that the impacted product may be end-of-life or end-of-service and advises users to discontinue use or move to a supported version.
Technical details
- CVE: CVE-2023-22894, published 19 April 2023.
- Weakness: CWE-312, cleartext storage of sensitive information.
- CVSS 3.1: 4.9 (medium), vector AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N. In plain terms: reachable over the network, low complexity, but it needs high privileges (an admin account), and it only affects confidentiality.
- KEV: added 8 October 2026, due date 11 October 2026.
- Ransomware use: unknown, according to CISA.
- EPSS: 0.01658 (about 1.7%), the modelled probability of exploitation in the next 30 days.
The low EPSS and medium CVSS score sit awkwardly beside the KEV listing. KEV reflects observed exploitation, so it should outweigh the scores when you prioritise.
Why this matters
This section is our analysis, not new reported fact.
The CVSS score is modest because an attacker first needs an admin login. In practice that is not much comfort. Stolen or phished admin credentials, a shared account, or a lower-trust contributor with panel access are all realistic starting points. Once inside, the leaked password hashes and reset tokens could let an attacker take over further accounts, and the RCE chain CISA mentions raises the stakes for any internet-facing instance.
Because this is in KEV, patch or mitigate within hours to days rather than waiting for a normal maintenance window, especially on internet-facing Strapi admin panels.
What to do: how to fix the Strapi flaw
- Identify every Strapi instance, including staging and forgotten ones, and record its version.
- Upgrade anything below 4.8.0 to a current, supported release. Check the Strapi release notes and security disclosure at the vendor’s pages linked below.
- If you cannot upgrade, apply the vendor’s mitigations and restrict the admin panel to trusted networks or a VPN. CISA says to discontinue use if mitigations are unavailable.
- Review who holds admin and super admin roles and remove accounts that are not needed.
- Assume exposure on unpatched, reachable instances: rotate admin and API user passwords and invalidate outstanding password reset tokens.
- Check CVE-2023-22621 as well, since CISA links the two.
Detection and hunting ideas
No indicators of compromise have been published in the sources. Based on how the flaw works, defenders can reasonably look for:
- Admin panel logins from unfamiliar IP addresses or at unusual times.
- Unusual volumes of user-list API requests that use query filters on sensitive user fields.
- Unexpected password resets or new admin accounts after such activity.
Sources
- CISA Known Exploited Vulnerabilities catalog entry for CVE-2023-22894
- NVD: CVE-2023-22894
- Strapi security disclosure of vulnerabilities
- Strapi releases on GitHub
