The US cyber agency CISA added a Strapi flaw to its list of known exploited vulnerabilities on 8 October 2026. The bug is tracked as CVE-2023-22894. Strapi is a content management system. The NIST National Vulnerability Database says versions up to 4.5.5 are affected. A user with admin panel access can abuse the search filter to work out sensitive user details from the system's replies. A super admin could learn every user's password hash and password reset token. CISA set a federal due date of 11 October 2026.
NIST rated the flaw 4.9, which is medium, and notes the attacker needs high privileges. CISA says it can be chained with a second bug, CVE-2023-22621, to run code remotely. CISA lists whether ransomware gangs use it as unknown. The sources do not say who is exploiting it, how many sites are hit, or how the attacks work. They also do not name a fixed Strapi version. CISA says affected products may be end-of-life, meaning no longer supported.
Teams that run Strapi, or buy products built on it, should check which version is live and who can reach the admin panel. CISA tells users to follow vendor instructions or stop using the product if no fix exists. Its listing means the flaw is used in real attacks, even with a medium score.