CVE-2026-108114: Strapi
Medium severity, CVSS 4.3.
Strapi 5.47.0 through 5.57.0 contains an improper authorization vulnerability that allows admin API tokens to retain all-field Content Manager access after the owner's role is field-restricted. Because reconcileTokenPermissionsToUserCeiling ignores token permissions with omitted or null fields, token holders can keep reading content fields an administrator removed from the role.
Affected products
- Strapi Strapi: from 5.47.0, up to and including 5.57.0
Published 2026-10-10. Last modified 2026-10-10.