DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-105845: CVE-2026-105845: SQL Injection and Access Control Bypass in Payload CMS Adapters via Case-Sensitivity Flaws and Sorting

CVE-2026-105845: SQL Injection and Access Control Bypass in Payload CMS Adapters via Case-Sensitivity Flaws and Sorting

Vulnerability ID: CVE-2026-105845
CVSS Score: 9.8
Published: 2026-10-06

A critical SQL Injection and access control bypass vulnerability was identified in Payload CMS database adapters (SQLite and PostgreSQL using Drizzle ORM internally). The vulnerability arises from case-sensitive logical operator checks during path validation and unvalidated sort queries. This allows remote attackers to bypass access control rules, execute unauthorized queries, and retrieve sensitive data through blind SQL injection side channels.

TL;DR

Remote attackers can bypass Payload CMS field access controls and perform blind SQL injection or unauthorized sorting by using capitalized logical operators like 'AND' or 'OR' and utilizing unvalidated query sorting parameters.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-89
  • Attack Vector: Network (AV:N)
  • CVSS Score: 9.8 (Critical)
  • Exploit Status: PoC / Analytical
  • KEV Status: Not Listed
  • Ransomware Use: No

Affected Systems

  • Payload CMS (SQLite Adapter)
  • Payload CMS (Postgres Adapter)
  • Applications utilizing Drizzle ORM adapters within Payload CMS versions 3.0.0 up to 3.87.9
  • payload: >= 3.0.0, < 3.88.0 (Fixed in: 3.88.0)
  • payload: >= 4.0.0-canary.0, < 4.0.0-canary.27 (Fixed in: 4.0.0-canary.27)

Code Analysis

Commit: a742140

fix(core): validate query sorting, handle lowercase/uppercase operators, and reject unmapped constraint arrays

Mitigation Strategies

  • Upgrade Payload CMS to version 3.88.0 or higher.
  • Configure WAF rules to block mixed-case or uppercase logical query keys (e.g., AND, OR, And).
  • Enforce strict least-privilege access rules at the database engine level.

Remediation Steps:

  1. Identify vulnerable Payload CMS installations by inspecting package.json for versions between 3.0.0 and 3.87.9.
  2. Run npm install payload@3.88.0 or update yarn/pnpm equivalent to pull the patched version.
  3. Verify that the fix is applied by attempting a test query using mixed-case logical operators and ensuring it is rejected with a validation error.
  4. Deploy the updated application to production and monitor API logs for blocked query formats.

References


Read the full report for CVE-2026-105845 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)