Skip to content
Brief Security & Trust ·

US adds Strapi data-exposure flaw to its list of exploited bugs

CISA says attackers are using a 2023 flaw in the Strapi content system, and agencies must act by 11 October.

In brief
  • CISA put Strapi flaw CVE-2023-22894 on its Known Exploited Vulnerabilities list on 8 October 2026. Federal agencies have until 11 October to respond.
  • The flaw affects Strapi up to version 4.5.5 and needs admin panel access. CISA says it can be chained with another bug to run code remotely.

The US cyber agency CISA added a Strapi flaw to its list of known exploited vulnerabilities on 8 October 2026. The bug is tracked as CVE-2023-22894. Strapi is a content management system. The NIST National Vulnerability Database says versions up to 4.5.5 are affected. A user with admin panel access can abuse the search filter to work out sensitive user details from the system's replies. A super admin could learn every user's password hash and password reset token. CISA set a federal due date of 11 October 2026.

NIST rated the flaw 4.9, which is medium, and notes the attacker needs high privileges. CISA says it can be chained with a second bug, CVE-2023-22621, to run code remotely. CISA lists whether ransomware gangs use it as unknown. The sources do not say who is exploiting it, how many sites are hit, or how the attacks work. They also do not name a fixed Strapi version. CISA says affected products may be end-of-life, meaning no longer supported.

Teams that run Strapi, or buy products built on it, should check which version is live and who can reach the admin panel. CISA tells users to follow vendor instructions or stop using the product if no fix exists. Its listing means the flaw is used in real attacks, even with a medium score.

A WebPulse Brief: a short report of an important event, written by the WebPulse Newsroom with AI assistance and checked against the reporting below. When there is more to explain, we follow up with a full story. How we use AI.

Reporting: CISA Known Exploited Vulnerabilities.