---
id: CVE-2026-46645
aliases:
  - GHSA-54mc-gghv-4cfj
  - PYSEC-2026-3073
title: 'SQLAdmin: Authorization Bypass on `ajax_lookup`'
summary: 'SQLAdmin: Authorization Bypass on `ajax_lookup`'
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'
vendor: sqladmin
product: sqladmin
ecosystem: pip
affected:
  - sqladmin < 0.25.1
patched:
  - sqladmin 0.25.1
published: '2026-05-21'
updated: '2026-07-13'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-54mc-gghv-4cfj'
references:
  - url: >-
      https://github.com/smithyhq/sqladmin/security/advisories/GHSA-54mc-gghv-4cfj
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-46645'
  - url: 'https://github.com/smithyhq/sqladmin/pull/1035'
  - url: >-
      https://github.com/smithyhq/sqladmin/commit/b0d3a19fb9b074a9ed243de46930108375dfbb98
  - url: 'https://github.com/smithyhq/sqladmin'
  - url: 'https://github.com/smithyhq/sqladmin/releases/tag/0.25.1'
tags:
  - osv
  - pip
  - exploit-available
epss: 0.00279
epssPercentile: 0.2064
ingestedAt: '2026-07-13T18:57:52.999Z'
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/rootdirective-sec/CVE-2026-46645-Analysis-Lab'
  checkedAt: '2026-09-24T07:53:04.379Z'
exploitAvailable: true
---

## Overview

### Impact

The `ajax_lookup` endpoint in `application.py` bypasses the `is_accessible()` access control check that all other endpoints enforce.

If a developer restricts model access by overriding `is_accessible()`, an authenticated user can still query that model's data through the `ajax_lookup` endpoint — silently bypassing the restriction.

**Affected endpoint:**

`GET /{identity}/ajax/lookup?name=<field>&term=<query>`

**All other endpoints enforce both checks:**

| Endpoint | `@login_required` | `is_accessible()` |
|---|---|---|
| `list` | ✓ | ✓ |
| `create` | ✓ | ✓ |
| `edit` | ✓ | ✓ |
| `delete` | ✓ | ✓ |
| `details` | ✓ | ✓ |
| `export` | ✓ | ✓ |
| `ajax_lookup` (before fix) | ✗ | ✗ |
| `ajax_lookup` (after fix) | ✓ | ✓ |

Note: before this fix, `ajax_lookup` also lacked the `@login_required` decorator — unauthenticated users could query it directly. That was addressed in #1035. This report covers the remaining gap: authenticated but unauthorized users.

### Patches

Two changes were made to `ajax_lookup`:

1. Replaced the hand-rolled authentication check added in #1035 with the standard `@login_required` decorator used by all other endpoints.
2. Added the missing `is_accessible(request)` check, raising `HTTP 403` when it returns `False`.

### Workarounds

None. Developers relying on `is_accessible()` to restrict model visibility are exposed regardless of what other access controls are in place.

## Affected packages

- `sqladmin < 0.25.1`

## Remediation

Upgrade to a patched release:

- `sqladmin 0.25.1`
