Vulnerability record · CVE-2019-18818 · published 7 November 2019
CVE-2019-18818: Strapi password reset mishandling enables account takeover
Strapi · Strapi
Strapi before 3.0.0-beta.17.5 mishandles password resets in the admin and users-permissions Auth controllers. The flaw is classified as CWE-640 (weak password recovery), meaning the reset flow can be abused to take over accounts. Because Strapi admin accounts control CMS content and configuration, this is a serious exposure for any unpatched instance.
Description
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/strapi-plugin-users-permissions/controllers/Auth.js.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or user interaction required, near-maximum EPSS, and public exploit write-ups covering authentication bypass, privilege escalation and RCE.
What it is
Strapi before 3.0.0-beta.17.5 mishandles password resets in the admin and users-permissions Auth controllers. The flaw is classified as CWE-640 (weak password recovery), meaning the reset flow can be abused to take over accounts. Because Strapi admin accounts control CMS content and configuration, this is a serious exposure for any unpatched instance.
Impact
An attacker can bypass the intended password recovery process and gain control of user or administrator accounts. On an admin account this yields full control of the CMS, and public exploit write-ups for this version line also cover authentication bypass, privilege escalation and remote code execution.
Attack surface
The vulnerable code sits in the authentication controllers of the admin panel and the users-permissions plugin, reachable over the network via the password reset endpoints. The CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.97639, 99.9th percentile) and multiple references are tagged Exploit, including Packet Storm authentication bypass, privilege escalation and RCE write-ups. Treat exploitation as likely and publicly available.
What to do
- Upgrade Strapi to 3.0.0-beta.17.5 or later; this is the fixed release referenced in the advisory.
- If immediate upgrade is not possible, restrict network access to the admin panel and password reset endpoints to trusted addresses.
- Audit all accounts for unexpected password or email changes and force credential resets for administrators.
- Review the referenced pull request and npm advisory to confirm the exact code paths and verify the fix is present in your build.
- Monitor Strapi release notes for follow-on fixes, since public RCE and privilege escalation write-ups target the same version line.
Detection
- Alert on password reset requests for admin or privileged accounts, especially bursts or resets followed by immediate logins from new IPs.
- Review Strapi authentication and password reset logs for requests that skip or alter the normal token verification flow.
- Hunt for new or modified admin accounts and permission changes in the users-permissions plugin after any reset activity.
- Correlate outbound or inbound traffic to Strapi admin endpoints with known exploit tooling user agents or payload patterns.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2019-18818 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-18818), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.