CVE-2026-105805: Sorting-Based Side-Channel Information Disclosure in Payload CMS
Vulnerability ID: CVE-2026-105805
CVSS Score: 6.9
Published: 2026-10-06
CVE-2026-105805 is an authorization bypass and information disclosure vulnerability in Payload CMS. Before version 3.88.0, user-controlled sorting was executed at the database level before field-level access control rules and data redaction were applied. This allowed unauthorized users to reconstruct restricted field values through a sorting side-channel.
TL;DR
An authorization bypass vulnerability in Payload CMS enables unauthenticated users to deduce hidden values in restricted fields (such as passphrases, tokens, or boolean flags) by leveraging sorting parameters to alter the physical order of returned API records.
Technical Details
- CWE ID: CWE-863 / CWE-200
- Attack Vector: Network
- CVSS Score: 6.9 (Medium)
- Exploit Status: None
- CISA KEV Status: Not Listed
- Vulnerability Type: Incorrect Authorization (Sorting Side-Channel)
Affected Systems
- Payload CMS
-
Payload CMS: < 3.88.0 (Fixed in:
3.88.0) -
Payload CMS: >= 4.0.0-canary.0, < 4.0.0-canary.27 (Fixed in:
4.0.0-canary.27)
Code Analysis
Commit: a742140
Introduce validateSortQuery to validate sort parameter paths before executing database sorting
Mitigation Strategies
- Upgrade Payload CMS dependencies to v3.88.0 or v4.0.0-canary.27 immediately.
- Deploy custom Express or application middleware to inspect and sanitize HTTP query sort parameters.
- Hardcode default sort parameters on critical collections to disable user-controlled sorting inputs on sensitive endpoints.
Remediation Steps:
- Identify the current installation version of Payload CMS in package.json.
- Execute dependency upgrade instructions to pull down version 3.88.0 or above.
- Review custom access control logic in schema definitions to ensure restricted fields are properly configured.
- Enable query-level logging on database systems to verify query parameters are properly verified before processing.
References
- Official GitHub Advisory GHSA-9g87-32v6-3c2r
- Core Mitigation Implementation Patch
- Payload CMS v3.88.0 Official Release Changelog
- NVD Vulnerability Details Reference Page
- Official CVE.org Record Details
Read the full report for CVE-2026-105805 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)