« Volver al listado

CVE-2026-46645

Estado: AplazadaMedia (4.3)—

SQLAdmin is a flexible Admin interface for SQLAlchemy models. Prior to version 0.25.1, the ajax_lookup endpoint in application.py bypasses the is_accessible() access control check that all other endpoints enforce. If a developer restricts model access by overriding is_accessible(), an authenticated user can still query that model's data through the ajax_lookup endpoint — silently bypassing the restriction. This issue has been patched in version 0.25.1.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-46645",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-46645",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-06-11T14:49:02.169261Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "smithyhq",
          "product": "sqladmin",
          "versions": [
            {
              "status": "affected",
              "version": "< 0.25.1"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-06-10T23:16:47.310",
  "references": [
    {
      "url": "https://github.com/smithyhq/sqladmin/commit/b0d3a19fb9b074a9ed243de46930108375dfbb98",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/smithyhq/sqladmin/pull/1035",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/smithyhq/sqladmin/releases/tag/0.25.1",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/smithyhq/sqladmin/security/advisories/GHSA-54mc-gghv-4cfj",
      "source": "security-advisories@github.com"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-862"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "SQLAdmin is a flexible Admin interface for SQLAlchemy models. Prior to version 0.25.1, the ajax_lookup endpoint in application.py bypasses the is_accessible() access control check that all other endpoints enforce. If a developer restricts model access by overriding is_accessible(), an authenticated user can still query that model's data through the ajax_lookup endpoint — silently bypassing the restriction. This issue has been patched in version 0.25.1."
    },
    {
      "lang": "es",
      "value": "SQLAdmin es una interfaz de administración flexible para modelos de SQLAlchemy. Antes de la versión 0.25.1, el endpoint ajax_lookup en application.py omite la verificación de control de acceso is_accessible() que todos los demás endpoints aplican. Si un desarrollador restringe el acceso a un modelo al sobrescribir is_accessible(), un usuario autenticado aún puede consultar los datos de ese modelo a través del endpoint ajax_lookup - eludiendo silenciosamente la restricción. Este problema ha sido parcheado en la versión 0.25.1."
    }
  ],
  "lastModified": "2026-07-23T09:10:00.113",
  "sourceIdentifier": "security-advisories@github.com"
}