{"id":"CVE-2026-46645","aliases":["GHSA-54mc-gghv-4cfj","PYSEC-2026-3073"],"url":"https://o3.security/vulnerability/CVE-2026-46645","summary":"SQLAdmin: Authorization Bypass on `ajax_lookup`","details":"### Impact\n\nThe `ajax_lookup` endpoint in `application.py` bypasses the `is_accessible()` access control check that all other endpoints enforce.\n\nIf a developer restricts model access by overriding `is_accessible()`, an authenticated user can still query that model's data through the `ajax_lookup` endpoint — silently bypassing the restriction.\n\n**Affected endpoint:**\n\n`GET /{identity}/ajax/lookup?name=<field>&term=<query>`\n\n**All other endpoints enforce both checks:**\n\n| Endpoint | `@login_required` | `is_accessible()` |\n|---|---|---|\n| `list` | ✓ | ✓ |\n| `create` | ✓ | ✓ |\n| `edit` | ✓ | ✓ |\n| `delete` | ✓ | ✓ |\n| `details` | ✓ | ✓ |\n| `export` | ✓ | ✓ |\n| `ajax_lookup` (before fix) | ✗ | ✗ |\n| `ajax_lookup` (after fix) | ✓ | ✓ |\n\nNote: before this fix, `ajax_lookup` also lacked the `@login_required` decorator — unauthenticated users could query it directly. That was addressed in #1035. This report covers the remaining gap: authenticated but unauthorized users.\n\n### Patches\n\nTwo changes were made to `ajax_lookup`:\n\n1. Replaced the hand-rolled authentication check added in #1035 with the standard `@login_required` decorator used by all other endpoints.\n2. Added the missing `is_accessible(request)` check, raising `HTTP 403` when it returns `False`.\n\n### Workarounds\n\nNone. Developers relying on `is_accessible()` to restrict model visibility are exposed regardless of what other access controls are in place.","published":"2026-06-10T22:23:57.397Z","modified":"2026-08-12T03:51:08.363613261Z","cvss":{"score":4.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"},"epss":{"score":0.00279,"percentile":0.20449,"asOf":"2026-09-16"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"sqladmin","fixedVersion":"0.25.1"}],"fix":{"url":"https://github.com/smithyhq/sqladmin/commit/b0d3a19fb9b074a9ed243de46930108375dfbb98","label":"smithyhq/sqladmin@b0d3a19"},"references":[{"type":"WEB","url":"https://github.com/smithyhq/sqladmin/releases/tag/0.25.1"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/46xxx/CVE-2026-46645.json"},{"type":"ADVISORY","url":"https://github.com/smithyhq/sqladmin/security/advisories/GHSA-54mc-gghv-4cfj"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-46645"},{"type":"FIX","url":"https://github.com/smithyhq/sqladmin/commit/b0d3a19fb9b074a9ed243de46930108375dfbb98"},{"type":"FIX","url":"https://github.com/smithyhq/sqladmin/pull/1035"},{"type":"PACKAGE","url":"https://github.com/smithyhq/sqladmin"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:08.363613261Z"}}