DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-105805: CVE-2026-105805: Sorting-Based Side-Channel Information Disclosure in Payload CMS

CVE-2026-105805: Sorting-Based Side-Channel Information Disclosure in Payload CMS

Vulnerability ID: CVE-2026-105805
CVSS Score: 6.9
Published: 2026-10-06

CVE-2026-105805 is an authorization bypass and information disclosure vulnerability in Payload CMS. Before version 3.88.0, user-controlled sorting was executed at the database level before field-level access control rules and data redaction were applied. This allowed unauthorized users to reconstruct restricted field values through a sorting side-channel.

TL;DR

An authorization bypass vulnerability in Payload CMS enables unauthenticated users to deduce hidden values in restricted fields (such as passphrases, tokens, or boolean flags) by leveraging sorting parameters to alter the physical order of returned API records.


Technical Details

  • CWE ID: CWE-863 / CWE-200
  • Attack Vector: Network
  • CVSS Score: 6.9 (Medium)
  • Exploit Status: None
  • CISA KEV Status: Not Listed
  • Vulnerability Type: Incorrect Authorization (Sorting Side-Channel)

Affected Systems

  • Payload CMS
  • Payload CMS: < 3.88.0 (Fixed in: 3.88.0)
  • Payload CMS: >= 4.0.0-canary.0, < 4.0.0-canary.27 (Fixed in: 4.0.0-canary.27)

Code Analysis

Commit: a742140

Introduce validateSortQuery to validate sort parameter paths before executing database sorting

Mitigation Strategies

  • Upgrade Payload CMS dependencies to v3.88.0 or v4.0.0-canary.27 immediately.
  • Deploy custom Express or application middleware to inspect and sanitize HTTP query sort parameters.
  • Hardcode default sort parameters on critical collections to disable user-controlled sorting inputs on sensitive endpoints.

Remediation Steps:

  1. Identify the current installation version of Payload CMS in package.json.
  2. Execute dependency upgrade instructions to pull down version 3.88.0 or above.
  3. Review custom access control logic in schema definitions to ensure restricted fields are properly configured.
  4. Enable query-level logging on database systems to verify query parameters are properly verified before processing.

References


Read the full report for CVE-2026-105805 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)