CVE-2026-22706: Strapi: Password Reset Does Not Revoke Existing Refresh Sessions
- CVE: CVE-2026-22706
- CVSS v3.1 Vector:
CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N(2.1 — Low) - Affected Versions:
@strapi/adminand@strapi/plugin-users-permissions<=5.33.2 - How to Patch: Immediately update your Strapi to >=5.33.3
References
Code Behaviors & Features
Detect and mitigate CVE-2026-22706 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →