Home

Description

A security flaw has been discovered in FastApiAdmin up to 2.2.0. Affected by this vulnerability is the function reset_api_docs of the file /backend/app/plugin/init_app.py of the component Custom Documentation Endpoint. The manipulation results in information disclosure. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks.

PUBLISHED Reserved 2026-02-22 | Published 2026-02-23 | Updated 2026-02-23 | Assigner VulDB




MEDIUM: 6.9CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P
MEDIUM: 5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R
MEDIUM: 5.3CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R
5.0AV:N/AC:L/Au:N/C:P/I:N/A:N/E:POC/RL:ND/RC:UR

Problem types

Information Disclosure

Improper Access Controls

Timeline

2026-02-22:Advisory disclosed
2026-02-22:VulDB entry created
2026-02-22:VulDB entry last update

References

vuldb.com/?id.347359 (VDB-347359 | FastApiAdmin Custom Documentation Endpoint init_app.py reset_api_docs information disclosure) vdb-entry technical-description

vuldb.com/?ctiid.347359 (VDB-347359 | CTI Indicators (IOB, IOC, TTP, IOA)) signature permissions-required

vuldb.com/?submit.756067 (Submit #756067 | fastapiadmin <= 2.2.0 Exposure of Sensitive System Information to an Unauthorized Cont) third-party-advisory

github.com/...ties/tree/master/fastapi-admin/vulnerability-1 exploit

cve.org (CVE-2026-2975)

nvd.nist.gov (CVE-2026-2975)

Download JSON