CVE-2026-22706
Last modified
CVE-2026-22706 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Strapi is an open source headless content management system. In Strapi versions prior to 5.33.3, changing or resetting a user's password did not invalidate the user's existing refresh-token sessions by default. EPSS estimates a 0.27% chance of exploitation in the next 30 days.
Description
Strapi is an open source headless content management system. In Strapi versions prior to 5.33.3, changing or resetting a user's password did not invalidate the user's existing refresh-token sessions by default. The refresh-token invalidation step in the users-permissions and admin authentication controllers was conditional on a caller-supplied `deviceId`. When a password change or reset request did not include a `deviceId`, no refresh tokens were revoked, leaving every prior session active. An attacker who had previously obtained a refresh token could continue minting new access tokens after the legitimate user reset their password, allowing persistent unauthorized access for the lifetime of the refresh token (up to 30 days by default). Rotating credentials no longer terminated an active attacker session, defeating password reset as a containment measure. The patch in version 5.33.3 invalidates all refresh tokens associated with the user on every password change and password reset, regardless of whether a `deviceId` is supplied. A new device-scoped session is then issued to the caller as part of the response.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Strapi | Strapi | < 5.33.3 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-22706?
How severe is CVE-2026-22706?
How do I fix CVE-2026-22706?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-22700RustCrypto: Elliptic Curves is general purpose Elliptic Curv…7.5
- CVE-2026-22701filelock is a platform-independent file lock for Python. Pri…5.3
- CVE-2026-22702virtualenv is a tool for creating isolated virtual python en…4.5
- CVE-2026-22703Cosign provides code signing and transparency for containers…5.5
- CVE-2026-22704HAX CMS helps manage microsite universe with PHP or NodeJs b…5.4
- CVE-2026-22705RustCrypto: Signatures offers support for digital signatures…6.4
- CVE-2026-22707Strapi is an open source headless content management system.…5.4
- CVE-2026-22708Cursor is a code editor built for programming with AI. Prior…9.8
- CVE-2026-22709vm2 is an open source vm/sandbox for Node.js. In vm2 prior t…10
- CVE-2026-2271A flaw was found in GIMP's PSP (Paint Shop Pro) file parser.…5.5
- CVE-2026-22710Improper Neutralization of Input During Web Page Generation …5.4
- CVE-2026-22711Improper neutralization of alternate XSS syntax vulnerabilit…6.9
Are you affected by CVE-2026-22706?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
