Strapi may leak sensitive data via relational filtering due to lack of query sanitization
CVE: CVE-2026-27886 CVSS v3.1 Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N (9.3 — Critical) Affected Versions: @strapi/strapi <=5.36.1 How to Patch: Immediately update your Strapi to >=5.37.0