CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



CVE-2026-105845

CVE-2026-105845: SQL Injection and Access Control Bypass in Payload CMS Adapters via Case-Sensitivity Flaws and Sorting

Alon Barad
Alon Barad
Software Engineer

Oct 7, 2026·7 min read·2 visits

Executive Summary (TL;DR)

Remote attackers can bypass Payload CMS field access controls and perform blind SQL injection or unauthorized sorting by using capitalized logical operators like 'AND' or 'OR' and utilizing unvalidated query sorting parameters.

A critical SQL Injection and access control bypass vulnerability was identified in Payload CMS database adapters (SQLite and PostgreSQL using Drizzle ORM internally). The vulnerability arises from case-sensitive logical operator checks during path validation and unvalidated sort queries. This allows remote attackers to bypass access control rules, execute unauthorized queries, and retrieve sensitive data through blind SQL injection side channels.

Vulnerability Overview

The vulnerability CVE-2026-105845 affects the open-source headless Content Management System Payload CMS. It specifically resides within the query validation layers and affects both the SQLite and PostgreSQL adapters which rely internally on Drizzle ORM for database abstraction. The primary role of the query validation layer is to restrict API queries according to the access control permissions defined for specific collections, globals, and individual fields. When users specify dynamic filters on endpoints, the validation layer is responsible for inspecting the query paths and ensuring that the requesting entity holds sufficient read privileges for every field referenced.

This vulnerability undermines these access restrictions by presenting two distinct vectors. First, the query path validation algorithm fails to identify and recursively validate nested logical constraints if they are defined with mixed-case or uppercase logical operators. Second, query sorting parameter parsing fails to evaluate field-level read permissions, permitting attackers to sort results based on values inside hidden or restricted fields. The exploitation of these issues does not require administrative rights or victim interaction, creating a wide attack surface for deployments with exposed public-facing endpoints.

By combining the logical operator case bypass and the unauthenticated sorting parameter vulnerability, an attacker can construct queries that leak arbitrary database fields. This results in complete exposure of the backend data model. Systems running affected versions of Payload CMS are highly susceptible to unauthorized data exfiltration, including user credentials, API tokens, and internal configuration details.

Root Cause Analysis

The core of the access control bypass in validateQueryPaths.ts lies in the strict string comparison used to identify logical operators. In the vulnerable implementation, the query validator specifically checked if the current path exactly matched the lowercase strings 'and' or 'or' prior to executing recursive checks on nested arrays of conditions. This logic did not utilize case-insensitive comparison or string normalization. Consequently, when an operator such as 'AND', 'OR', or 'And' was provided, the conditional path check evaluated to false, skipping the nested validation block entirely.

Because the logical operator path check evaluated to false, the query path processor fell back to alternative check branches. The processor encountered a branch that evaluated single field constraints but required the constraint to not be an array. Since logical conditions are formatted as arrays of criteria, this check also evaluated to false. As a result, the validator terminated processing of the operator sub-tree without pushing any validation errors to the error collector, rendering the nested constraint implicitly valid.

Once the validator successfully bypassed verification of the query, the raw query tree was forwarded to the query execution engine. The underlying database adapters, which utilize Drizzle ORM, parse dynamic query parameters in a case-insensitive manner. Drizzle ORM correctly interprets 'AND' and 'OR' as logical operators, resulting in the direct generation of SQL statements containing the unvalidated nested constraints. Consequently, the database executes instructions containing criteria referencing fields that the user does not have permission to view.

Code-Level Analysis

To understand the patch, we examine the logic within validateQueryPaths.ts before and after the security update. The vulnerable code restricted its matching criteria to lowercase literals, failing to capture alternate casings. In addition, the parser lacked a catch-all mechanism to reject unvalidated arrays that failed to match the defined logical operator structure, leaving a logic gap that allowed nested structures to bypass verification entirely.

// Vulnerable Code Path
if ((path === 'and' || path === 'or') && Array.isArray(constraint)) {
  for (const item of constraint) {
    if (collectionConfig) {
      promises.push(
        validateQueryPaths({
          // ... recursive validation parameters
        })
      )
    }
  }
}

The remediation applied in commit a742140ab4fca3160f7f83e9e7d996552ffc3b5a introduces string normalization and a strict validation fallback. The modified logic converts the query path to lowercase using .toLowerCase() before evaluating whether it is a logical operator. Crucially, the patch also introduces an explicit else if (Array.isArray(constraint)) block. If an array is passed that does not match a valid logical operator, the validator now flags this as an error and rejects the query, preventing arbitrary arrays from bypassing validation.

// Patched Code Path
if (['and', 'or'].includes(path.toLowerCase()) && Array.isArray(constraint)) {
  for (const item of constraint) {
    if (collectionConfig) {
      promises.push(
        validateQueryPaths({
          // ... recursive validation parameters
        })
      )
    }
  }
} else if (Array.isArray(constraint)) {
  errors.push({ path })
}

Exploitation & Proof-of-Concept Analysis

Exploitation of CVE-2026-105845 relies on exploiting the differences between the casing assumptions of the validation engine and the query compiler. Under normal operation, a query to a protected field such as secretHash would be rejected by Payload's validation engine. An attacker can circumvent this protection by nesting the restricted path within a capitalized AND array parameter, which disables validation processing for that branch.

An attacker sends a crafted request containing the capitalized filter query:

GET /api/posts?where[AND][0][secretHash][equals]=target_value HTTP/1.1
Host: vulnerable-app.local

The validation engine skips the nested array check, and the query is passed directly to the database. If a record matching the condition exists, the application returns a standard record representation, thereby confirming the existence of the specific value.

Another primary exploitation mechanism targets the unvalidated sorting mechanism. Database systems execute sorting operations prior to the serialization and sanitization phase of the API response. An attacker can supply a sort parameter referencing a restricted field such as apiKey or resetToken. By observing the sequential ordering of the returned public list across multiple requests, the attacker can systematically deduce the values of the restricted field through a binary search side-channel.

Impact Assessment

The security implications of this vulnerability are classified as critical, as indicated by its CVSS base score of 9.8. Exploitation can be achieved remotely without prior authentication, provided that the targeted API collection has query operations publicly enabled. Even in configurations where collections require authentication, any user with minimal API privileges can execute these queries to elevate their access or view restricted columns.

The impact on confidentiality is high. Attackers can read sensitive columns including password hashes, session identifiers, reset tokens, and system configurations. By leveraging the blind sorting side-channel, sensitive strings can be exfiltrated character-by-character over the network. This completely bypasses the column-level access controls designed to secure multi-tenant or multi-role environments.

The impact on integrity and availability depends heavily on the specific database engine and underlying configuration. In environments utilizing PostgreSQL, the potential exists to inject more complex SQL fragments or trigger heavy computational queries, leading to denial of service. The potential for data modification or deletion exists if the underlying database driver configuration permits multi-statement execution, although the primary vector demonstrated relies heavily on read-based blind exfiltration.

Remediation and Mitigation Strategies

The definitive solution for CVE-2026-105845 is to upgrade the Payload CMS dependencies to the designated patched releases. Organizations deploying Payload CMS version 3 must upgrade to version 3.88.0 or higher. For teams leveraging the 4.x prerelease branch, the patch is integrated within version 4.0.0-canary.27 and all subsequent canary or stable releases. Upgrades can be performed using standard package managers.

For environments where immediate upgrading is not possible, temporary mitigations should be applied at the network or reverse proxy layer. Web Application Firewalls (WAFs) should be configured with custom inspection rules designed to detect and block incoming request parameters that contain logical operator keys with uppercase or mixed-case characters inside query strings, such as where[AND], where[Or], or where[OR].

Additionally, database adapters should be configured with the least-privilege principle. Database connection strings used by the CMS should utilize users restricted to necessary database tables, with administrative tables completely isolated. Developers are advised to audit custom collection configurations to ensure that public query permissions are disabled for collections hosting sensitive information unless strictly required by business logic.

Official Patches

Payload CMSOfficial GitHub Security Advisory

Fix Analysis (1)

Technical Appendix

CVSS Score
9.8/ 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Systems

Payload CMS (SQLite Adapter)Payload CMS (Postgres Adapter)Applications utilizing Drizzle ORM adapters within Payload CMS versions 3.0.0 up to 3.87.9

Affected Versions Detail

Product
Affected Versions
Fixed Version
payload
Payload CMS
>= 3.0.0, < 3.88.03.88.0
payload
Payload CMS
>= 4.0.0-canary.0, < 4.0.0-canary.274.0.0-canary.27
AttributeDetail
CWE IDCWE-89
Attack VectorNetwork (AV:N)
CVSS Score9.8 (Critical)
Exploit StatusPoC / Analytical
KEV StatusNot Listed
Ransomware UseNo

MITRE ATT&CK Mapping

T1190Exploit Public-Facing Application
Initial Access
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The software constructs an SQL command using externally-influenced input, but it does not neutralize or incorrectly neutralizes elements that can alter the intended SQL command when it is sent to a database.

Vulnerability Timeline

Security patch committed internally to Payload repository
2026-08-11
CVE-2026-105845 details and security advisory published
2026-10-06
Payload CMS version 3.88.0 containing the fix is released
2026-10-06

References & Sources

  • [1]GitHub Security Advisory GHSA-v49j-62m6-pgrr
  • [2]Payload CMS Fix Commit a742140ab4fca3160f7f83e9e7d996552ffc3b5a

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•about 2 hours ago•CVE-2026-105844
9.3

CVE-2026-105844: Remote Code Execution via Prototype Pollution in @payloadcms/plugin-import-export

A critical prototype pollution vulnerability in the import-export plugin of Payload CMS allows unauthenticated remote attackers to bypass access controls and achieve remote code execution.

Alon Barad
Alon Barad
2 views•6 min read
•about 3 hours ago•CVE-2026-105806
8.6

CVE-2026-105806: Privilege Escalation and Missing Authorization in @payloadcms/plugin-mcp

CVE-2026-105806 is an improper access control vulnerability within the Model Context Protocol (MCP) plugin for Payload CMS. Authenticated users with low privileges can manipulate API key creation and mapping to associate keys with arbitrary users, including administrators. This allows total session takeovers and privilege escalation via MCP-authenticated API requests.

Alon Barad
Alon Barad
6 views•5 min read
•about 4 hours ago•CVE-2026-105848
6.4

CVE-2026-105848: Insufficient Access Control in Payload CMS Stripe REST Proxy

An access control vulnerability in `@payloadcms/plugin-stripe` allows authenticated low-privilege users to bypass authorization boundaries and execute arbitrary, highly privileged operations on the connected Stripe platform via an exposed REST proxy.

Alon Barad
Alon Barad
6 views•7 min read
•about 5 hours ago•CVE-2026-105851
9.3

CVE-2026-105851: Privilege Escalation via Field Access Control Bypass in Payload CMS Duplication Mechanism

A critical access control bypass vulnerability (CVE-2026-105851) in Payload CMS allows authenticated users to bypass field-level access controls during document duplication. By duplicating high-privilege documents, such as administrator accounts, standard users can inherit sensitive fields (e.g., role configurations or API keys), leading to privilege escalation.

Alon Barad
Alon Barad
6 views•7 min read
•about 6 hours ago•CVE-2026-105853
7.1

CVE-2026-105853: Sensitive Information Disclosure and Authentication Collection Boundary Bypass in Payload CMS

CVE-2026-105853 is a high-severity information disclosure vulnerability in Payload CMS that affects authentication-enabled collections. In vulnerable versions, the application fails to properly serialize and sanitize user documents during token refresh and password reset operations. This deficiency leaks hidden and read-restricted fields to unauthorized actors. Additionally, a logical flaw in token refresh validation allows low-privileged users to cross collection boundaries, exposing sensitive configuration details and administrative metadata.

Amit Schendel
Amit Schendel
6 views•5 min read
•about 7 hours ago•CVE-2026-105852
5.3

CVE-2026-105852: Authorization Bypass and Related-Document Oracle in Payload CMS

An authorization bypass vulnerability in Payload CMS enables unauthenticated attackers to query and infer the existence of restricted documents via nested relationship queries on public collections. This cross-document contamination flaw affects both MongoDB and Drizzle SQL database adapters, allowing unauthorized reads of relationship metadata.

Amit Schendel
Amit Schendel
5 views•6 min read