← Vulnerability feed

Vulnerability record · CVE-2019-18818 · published 7 November 2019

CVE-2019-18818: Strapi password reset mishandling enables account takeover

Strapi · Strapi

Strapi before 3.0.0-beta.17.5 mishandles password resets in the admin and users-permissions Auth controllers. The flaw is classified as CWE-640 (weak password recovery), meaning the reset flow can be abused to take over accounts. Because Strapi admin accounts control CMS content and configuration, this is a serious exposure for any unpatched instance.

9.8 CVSS 3.1 Critical EPSS 98% · top 0.1% CWE-640 · Weak password recovery
9.8CVSS 3.1 base score, v2 7.5
98%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References, 6 tagged exploit
17 Jun 2026Last modified by NVD

Description

strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/strapi-plugin-users-permissions/controllers/Auth.js.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 9.8 with no authentication or user interaction required, near-maximum EPSS, and public exploit write-ups covering authentication bypass, privilege escalation and RCE.

What it is

Strapi before 3.0.0-beta.17.5 mishandles password resets in the admin and users-permissions Auth controllers. The flaw is classified as CWE-640 (weak password recovery), meaning the reset flow can be abused to take over accounts. Because Strapi admin accounts control CMS content and configuration, this is a serious exposure for any unpatched instance.

Impact

An attacker can bypass the intended password recovery process and gain control of user or administrator accounts. On an admin account this yields full control of the CMS, and public exploit write-ups for this version line also cover authentication bypass, privilege escalation and remote code execution.

Attack surface

The vulnerable code sits in the authentication controllers of the admin panel and the users-permissions plugin, reachable over the network via the password reset endpoints. The CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates no authentication and no user interaction are required.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.97639, 99.9th percentile) and multiple references are tagged Exploit, including Packet Storm authentication bypass, privilege escalation and RCE write-ups. Treat exploitation as likely and publicly available.

What to do

  • Upgrade Strapi to 3.0.0-beta.17.5 or later; this is the fixed release referenced in the advisory.
  • If immediate upgrade is not possible, restrict network access to the admin panel and password reset endpoints to trusted addresses.
  • Audit all accounts for unexpected password or email changes and force credential resets for administrators.
  • Review the referenced pull request and npm advisory to confirm the exact code paths and verify the fix is present in your build.
  • Monitor Strapi release notes for follow-on fixes, since public RCE and privilege escalation write-ups target the same version line.

Detection

  • Alert on password reset requests for admin or privileged accounts, especially bursts or resets followed by immediate logins from new IPs.
  • Review Strapi authentication and password reset logs for requests that skip or alter the normal token verification flow.
  • Hunt for new or modified admin accounts and permission changes in the users-permissions plugin after any reset activity.
  • Correlate outbound or inbound traffic to Strapi admin endpoints with known exploit tooling user agents or payload patterns.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-18818 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-38507Strapi allocation without limits vulnerabilityStrapi is the an open-source headless content management system. Prior to version 4.12.1, there is a rate limit on the login function of Strapi's adm…EPSS 0.96%9.8CVE-2022-27263Strapi unrestricted file upload vulnerabilityAn arbitrary file upload vulnerability in the file upload module of Strapi v4.1.5 allows attackers to execute arbitrary code via a crafted file.EPSS 3.2%9.8CVE-2020-27664Strapi vulnerabilityadmin/src/containers/InputModalStepperProvider/index.js in Strapi before 3.2.5 has unwanted /proxy?url= functionality.EPSS 2.3%9.3CVE-2026-22599Strapi sql injection vulnerabilityStrapi is an open source headless content management system. In versions on the 4.x branch prior to 4.26.1 and on the 5.x branch prior to 5.33.2, a d…EPSS 1.2%9.2CVE-2026-27886Strapi path traversal vulnerabilityStrapi is an open source headless content management system. Strapi versions starting in 4.0.0 and prior to 5.37.0 did not sufficiently sanitize quer…EPSS 2.5%8.8CVE-2022-31367Strapi sql injection vulnerabilityStrapi before 3.6.10 and 4.x before 4.1.10 mishandles hidden attributes within admin API responses.EPSS 1.7%8.8CVE-2022-32114Strapi unrestricted file upload vulnerabilityAn unrestricted file upload vulnerability in the Add New Assets function of Strapi 4.1.12 allows attackers to conduct XSS attacks via a crafted PDF f…EPSS 2.0%8.8CVE-2022-30617Strapi vulnerabilityAn authenticated user with access to the Strapi admin panel can view private and sensitive data, such as email and password reset tokens, for other a…EPSS 1.5%

Source: NIST National Vulnerability Database (record CVE-2019-18818), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.