CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



CVE-2026-105805

CVE-2026-105805: Sorting-Based Side-Channel Information Disclosure in Payload CMS

Alon Barad
Alon Barad
Software Engineer

Oct 7, 2026·6 min read·3 visits

Executive Summary (TL;DR)

An authorization bypass vulnerability in Payload CMS enables unauthenticated users to deduce hidden values in restricted fields (such as passphrases, tokens, or boolean flags) by leveraging sorting parameters to alter the physical order of returned API records.

CVE-2026-105805 is an authorization bypass and information disclosure vulnerability in Payload CMS. Before version 3.88.0, user-controlled sorting was executed at the database level before field-level access control rules and data redaction were applied. This allowed unauthorized users to reconstruct restricted field values through a sorting side-channel.

Vulnerability Overview

Payload CMS is an open-source headless content management system. Within its architecture, developers define fields and associate access control rules to restrict sensitive properties (e.g., boolean flags, system tokens, hashed password strings) from public read access.

This security control is bypassed in vulnerable versions because database queries execute sorting logic on the raw, unredacted records prior to the application of field-level authorization and redaction logic.

An attacker with read access to a collection can exploit this behavioral sequence to construct a sorting-based side-channel (also called a sorting oracle). By passing custom sort parameters targeting restricted fields and analyzing the order of returned records, the attacker can infer hidden values.

Root Cause Analysis

The underlying technical flaw stems from incorrect authorization evaluation (CWE-863) combined with sensitive information exposure (CWE-200) within the query parsing logic of the CMS database adapters (such as MongoDB or Drizzle-managed SQL).

The processing sequence for collection query REST requests is structured as follows:

  1. The API endpoint receives query parameters, including the user-specified sort argument.
  2. The server translates this argument directly into a native database sorting directive and executes the query.
  3. The database returns the sorted, raw result set to the application backend.
  4. The application processes the records, evaluating field-level read permissions and stripping out values for which the requesting user lacks authorization.
  5. The sanitized JSON array is returned to the client.

Because database-level sorting occurs before post-query authorization redaction, the physical ordering of the document objects returned in the client response is determined by the values of the unauthorized fields. Although the JSON payload excludes the actual values, the structured position of the records reveals the comparative values of the hidden properties.

Code-Level Vulnerability & Patch Analysis

The vulnerability was resolved in commit a742140ab4fca3160f7f83e9e7d996552ffc3b5a by introducing a validation process called validateSortQuery.ts within the database query validation pipeline.

This validator maps the specified sorting fields to a temporary Where constraint structure and executes standard query validation logic against them. This ensures that a client cannot execute queries using sort parameters that reference fields they do not have the authorization to filter by.

// packages/payload/src/database/queryValidation/validateSortQuery.ts
import { validateQueryPaths } from './validateQueryPaths.js'
 
export const validateSortQuery = async ({
  collectionConfig,
  globalConfig,
  overrideAccess,
  req,
  sort,
  versionFields,
}: Args): Promise<void> => {
  if (overrideAccess || !sort) {
    return
  }
 
  const fields = versionFields || (globalConfig || collectionConfig).flattenedFields
  const sortFields = Array.isArray(sort) ? sort : [sort]
  const where: Where = {}
 
  for (const sortField of sortFields) {
    // Normalize sort arguments by stripping descending indicators and nested qualifiers
    const path = sortField.replace(/^-/, '').replace(/__/g, '.')
    const paths = getLocalizedPaths({
      collectionSlug: collectionConfig?.slug,
      fields,
      globalSlug: globalConfig?.slug,
      incomingPath: path,
      locale: req.locale!,
      overrideAccess: true,
      payload: req.payload,
    })
 
    if (path !== 'id' && path !== '_id' && paths.every(({ invalid }) => !invalid)) {
      where[path] = { exists: true }
    }
  }
 
  if (Object.keys(where).length === 0) {
    return
  }
 
  // Execute permissions check as if the client queried these paths directly in a filter
  if (collectionConfig) {
    await validateQueryPaths({
      collectionConfig,
      overrideAccess,
      req,
      versionFields,
      where,
    })
  } else {
    await validateQueryPaths({
      globalConfig,
      overrideAccess,
      req,
      versionFields,
      where,
    })
  }
}

This validator was integrated directly into find, findDistinct, findVersions, and update operation controllers. By routing the normalized sorting path into validateQueryPaths, the core permissions layer verifies if the requesting identity holds read capabilities on the field. If they do not, the application aborts the database transaction and responds with a validation error.

Exploitation Methodology

Exploiting this side-channel does not require system access or write capabilities. The attacker only needs access to a publicly queryable endpoint where custom sorting parameters are accepted.

To identify boolean-based hidden administrative flags (such as an isAdmin flag on a public profile list):

  1. The attacker queries the users collection sorted by the hidden parameter in ascending order: GET /api/users?sort=isAdmin The application returns the user objects sorted so that false (0) values appear at the beginning of the list, followed by true (1) values. The values of the isAdmin key are stripped.
  2. The attacker queries the collection sorted in descending order: GET /api/users?sort=-isAdmin This query forces true values to the top, and false values to the bottom.
  3. By comparing the relative positions of user IDs between the ascending and descending responses, the attacker identifies which specific records are assigned true versus false flags.

For alphanumeric secrets (e.g., reset tokens, keys), attackers can construct iterative binary search algorithms. By comparing the sorted positions of target documents against lexicographically known dummy records, they can systematically reconstruct sensitive data strings character by character.

Impact Assessment

The security impact of CVE-2026-105805 is categorized as medium (CVSS 6.9). The primary impact is unauthorized disclosure of sensitive parameters stored in databases. Attackers can leak restricted configuration flags, reset tokens, or backend attributes that are meant to be restricted.

Because this vulnerability resides in the core query processing structure of Payload CMS, it is widespread across any customized schemas that enforce field-level security while exposing custom client-defined sorting endpoints.

There is no recorded instance of active exploitation in the wild, and public weaponized exploit tools targeting this CVE have not been released. However, due to the logical simplicity of implementing sorting-based side-channel analyses, the exploitability potential is high.

Remediation and Defensive Guidance

The definitive fix for this vulnerability is upgrading the application to a patched version. Upgrade dependencies to version 3.88.0 or later, or version 4.0.0-canary.27 or later if using the canary release branch.

# Upgrade Payload CMS using npm
npm install payload@3.88.0

For systems where immediate updating is blocked, developers can implement Express-level parameter sanitization middleware. This middleware intercepts query payloads and strips out forbidden sort criteria before the query parameters reach the database adapter operation layer:

app.use('/api', (req, res, next) => {
  if (req.query && typeof req.query.sort === 'string') {
    const restrictedFields = ['password', 'resetToken', 'isAdmin', 'apiKey'];
    const normalizedPath = req.query.sort.replace(/^-/, '');
    
    if (restrictedFields.includes(normalizedPath)) {
      return res.status(403).json({
        error: 'Forbidden sorting parameter requested'
      });
    }
  }
  next();
});

Security teams should configure logging and alert rules on Web Application Firewalls (WAF) to detect successive requests featuring ascending and descending queries on the same schema fields, as this is a standard indicator of an automated extraction script mapping the sorting side-channel.

Official Patches

payloadcmsCore patch implementing validateSortQuery to resolve database sorting side-channel

Fix Analysis (1)

Technical Appendix

CVSS Score
6.9/ 10
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

Affected Systems

Payload CMS

Affected Versions Detail

Product
Affected Versions
Fixed Version
Payload CMS
payloadcms
< 3.88.03.88.0
Payload CMS
payloadcms
>= 4.0.0-canary.0, < 4.0.0-canary.274.0.0-canary.27
AttributeDetail
CWE IDCWE-863 / CWE-200
Attack VectorNetwork
CVSS Score6.9 (Medium)
Exploit StatusNone
CISA KEV StatusNot Listed
Vulnerability TypeIncorrect Authorization (Sorting Side-Channel)

MITRE ATT&CK Mapping

T1005Data from Local System
Collection
T1552Unsecured Credentials
Credential Access
T1068Exploitation for Privilege Escalation
Privilege Escalation
CWE-863
Incorrect Authorization

The software does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

Vulnerability Timeline

Strict path prefix checking logic patched (c6477b8)
2026-08-10
Core sorting verification mechanism patch committed (a742140)
2026-08-11
Payload CMS version 3.88.0 is officially released
2026-08-11
CVE-2026-105805 is published on NVD and CVE.org
2026-10-06

References & Sources

  • [1]Official GitHub Advisory GHSA-9g87-32v6-3c2r
  • [2]Core Mitigation Implementation Patch
  • [3]Payload CMS v3.88.0 Official Release Changelog
  • [4]NVD Vulnerability Details Reference Page
  • [5]Official CVE.org Record Details

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•22 minutes ago•CVE-2026-105795
3.1

CVE-2026-105795: Unvalidated Custom Extension Path Traversal in Microsoft Kiota

CVE-2026-105795 (GHSA-6gw6-rv2g-25mg) is a critical path traversal vulnerability in Microsoft Kiota, an OpenAPI-based HTTP client and plugin manifest generator. In affected versions (1.25.1 to < 1.35.0), Kiota propagates the unvalidated `x-ai-capabilities.response_semantics.oauth_card_path` vendor extension directly into generated API plugin manifests, leading to potential path traversal exploitation by downstream consumers.

Alon Barad
Alon Barad
0 views•6 min read
•about 2 hours ago•CVE-2026-105847
7.1

CVE-2026-105847: Information Disclosure via Polymorphic Join Queries in Payload CMS

Payload CMS is subject to an information disclosure vulnerability where users with query permissions can bypass field-level access controls. By leveraging polymorphic join filters, an attacker can perform blind-inference queries to retrieve restricted or hidden fields such as password reset tokens.

Amit Schendel
Amit Schendel
3 views•6 min read
•about 3 hours ago•CVE-2026-105846
6.1

CVE-2026-105846: Open Redirect in Payload CMS via Control Character Bypass

An open redirect vulnerability exists in Payload CMS within its Next.js-based authentication routing components. The sanitization utility fails to properly account for control characters and ambiguous encodings, allowing unauthenticated attackers to redirect users to external malicious domains after successful authentication.

Alon Barad
Alon Barad
4 views•6 min read
•about 4 hours ago•CVE-2026-105845
9.8

CVE-2026-105845: SQL Injection and Access Control Bypass in Payload CMS Adapters via Case-Sensitivity Flaws and Sorting

A critical SQL Injection and access control bypass vulnerability was identified in Payload CMS database adapters (SQLite and PostgreSQL using Drizzle ORM internally). The vulnerability arises from case-sensitive logical operator checks during path validation and unvalidated sort queries. This allows remote attackers to bypass access control rules, execute unauthorized queries, and retrieve sensitive data through blind SQL injection side channels.

Alon Barad
Alon Barad
6 views•7 min read
•about 5 hours ago•CVE-2026-105844
9.3

CVE-2026-105844: Remote Code Execution via Prototype Pollution in @payloadcms/plugin-import-export

A critical prototype pollution vulnerability in the import-export plugin of Payload CMS allows unauthenticated remote attackers to bypass access controls and achieve remote code execution.

Alon Barad
Alon Barad
4 views•6 min read
•about 6 hours ago•CVE-2026-105806
8.6

CVE-2026-105806: Privilege Escalation and Missing Authorization in @payloadcms/plugin-mcp

CVE-2026-105806 is an improper access control vulnerability within the Model Context Protocol (MCP) plugin for Payload CMS. Authenticated users with low privileges can manipulate API key creation and mapping to associate keys with arbitrary users, including administrators. This allows total session takeovers and privilege escalation via MCP-authenticated API requests.

Alon Barad
Alon Barad
10 views•5 min read