Listen to this Post
Payload CMS is a headless CMS and application framework.
The advisory concerns sort query handling in Payload.
Under certain conditions, sorting readable records can expose limited field information.
The exposure affects fields the requester was not permitted to read.
The issue is described as moderate severity.
It was reviewed by GitHub.
It was published on Sep 22, 2026.
It was updated on Oct 6, 2026.
The package is payloadcms/payload.
Affected versions are before 3.88.0.
Affected canary versions start at 4.0.0-canary.0.
Affected canary versions end before 4.0.0-canary.27.
Patched versions are 3.88.0.
Patched canary version is 4.0.0-canary.27.
The vulnerability involves query sorting.
Untrusted users must be able to query a collection.
They must be able to control sorting.
They must be able to sort by protected fields.
When these conditions align, sort behavior may reveal protected field information.
Payload previously did not apply field-level access checks to sort fields before executing queries.
The patch applies field-level access checks to sort fields.
This check occurs before query execution.
The fix prevents unauthorized sort fields from influencing query behavior.
Users should upgrade to 3.88.0 or later.
Users on canary should upgrade to 4.0.0-canary.27 or later.
Upgrading is the recommended remediation.
A temporary workaround is to prevent untrusted users from controlling sort parameters.
Another workaround is to restrict access to affected collections.
The source does not provide a CVE identifier.
No CVE identifier is invented here.
DailyCVE Form:
Platform: Payload CMS
Version: <3.88.0; canary <27
Vulnerability: Sort access bypass
Severity: Moderate
date: 2026-09-22
Prediction: 2026-10-06
What Undercode Say:
Analytics
curl -s 'https://target.example/api/posts?sort=-protectedField'
curl -G 'https://target.example/api/collection' \ --data-urlencode 'sort=-protectedField'
sort=-protectedField
Exploit: (Educational Purposes!)
curl -G 'https://target.example/api/collection' \ --data-urlencode 'sort=-protectedField' \ --data-urlencode 'limit=1'
curl -s 'https://target.example/api/collection?sort=-protectedField'
Protection: from this CVE
npm install [email protected] npm install [email protected]
Prevent untrusted sort control Restrict affected collections
Impact:
Under certain conditions, sorting readable records could reveal limited information about fields the requester was not permitted to read. You are affected if untrusted users can query a collection, control its sorting, and sort by protected fields.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

