CVE-2026-105845: SQL Injection and Access Control Bypass in Payload CMS Adapters via Case-Sensitivity Flaws and Sorting
Vulnerability ID: CVE-2026-105845
CVSS Score: 9.8
Published: 2026-10-06
A critical SQL Injection and access control bypass vulnerability was identified in Payload CMS database adapters (SQLite and PostgreSQL using Drizzle ORM internally). The vulnerability arises from case-sensitive logical operator checks during path validation and unvalidated sort queries. This allows remote attackers to bypass access control rules, execute unauthorized queries, and retrieve sensitive data through blind SQL injection side channels.
TL;DR
Remote attackers can bypass Payload CMS field access controls and perform blind SQL injection or unauthorized sorting by using capitalized logical operators like 'AND' or 'OR' and utilizing unvalidated query sorting parameters.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-89
- Attack Vector: Network (AV:N)
- CVSS Score: 9.8 (Critical)
- Exploit Status: PoC / Analytical
- KEV Status: Not Listed
- Ransomware Use: No
Affected Systems
- Payload CMS (SQLite Adapter)
- Payload CMS (Postgres Adapter)
- Applications utilizing Drizzle ORM adapters within Payload CMS versions 3.0.0 up to 3.87.9
-
payload: >= 3.0.0, < 3.88.0 (Fixed in:
3.88.0) -
payload: >= 4.0.0-canary.0, < 4.0.0-canary.27 (Fixed in:
4.0.0-canary.27)
Code Analysis
Commit: a742140
fix(core): validate query sorting, handle lowercase/uppercase operators, and reject unmapped constraint arrays
Mitigation Strategies
- Upgrade Payload CMS to version 3.88.0 or higher.
- Configure WAF rules to block mixed-case or uppercase logical query keys (e.g., AND, OR, And).
- Enforce strict least-privilege access rules at the database engine level.
Remediation Steps:
- Identify vulnerable Payload CMS installations by inspecting package.json for versions between 3.0.0 and 3.87.9.
- Run
npm install payload@3.88.0or update yarn/pnpm equivalent to pull the patched version. - Verify that the fix is applied by attempting a test query using mixed-case logical operators and ensuring it is rejected with a validation error.
- Deploy the updated application to production and monitor API logs for blocked query formats.
References
- GitHub Security Advisory GHSA-v49j-62m6-pgrr
- Payload CMS Fix Commit a742140ab4fca3160f7f83e9e7d996552ffc3b5a
Read the full report for CVE-2026-105845 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)