CISA added CVE-2023-22894 to its Known Exploited Vulnerabilities (KEV) catalogue on 8 October 2026. The vulnerability affects Strapi and is named the Strapi Cleartext Storage of Sensitive Information Vulnerability; it could expose sensitive user details to attackers with access to the admin panel.
The flaw involves sensitive information stored in cleartext and exposed through Strapi’s query filter. An attacker who can access the admin panel could use the filter to discover sensitive user details. The vulnerability has a CVSS score of 7.2, rated HIGH. It can be chained with CVE-2023-22621 to achieve remote code execution. Patch status is unknown, and no patch or advisory URL was provided.
CISA notes that affected products may be end-of-life or end-of-service, and advises users to discontinue use or transition to a supported version where applicable.
CVE-2023-22894’s inclusion in the KEV catalogue indicates that exploitation has been confirmed. Use in ransomware campaigns is unknown. CISA’s remediation deadline is 11 October 2026.
CISA requires organisations to apply mitigations in accordance with vendor instructions and comply with its BOD 26-04 guidance on prioritising security updates based on risk and its Forensics Triage Requirements. For cloud services, organisations should follow applicable BOD 26-04 guidance; if mitigations are unavailable, they should discontinue use of the product. FCEB agencies are directly subject to CISA’s requirements.
Stakeholders must evaluate each asset’s internet exposure and follow applicable BOD 26-04 patching guidance. All organisations should review their Strapi exposure, check whether affected assets are in use, and assess available vendor guidance.
For full details, see the [NVD entry for CVE-2023-22894](https://nvd.nist.gov/vuln/detail/CVE-2023-22894) and the [CISA KEV catalogue](https://www.cisa.gov/known-exploited-vulnerabilities-catalog).