Listen to this Post
CVE-2026-105845 is a critical SQL injection vulnerability affecting the Payload CMS (payloadcms/payload) when used with SQLite or Postgres adapters. The flaw resides in the handling of dynamic query filters and join parameters supplied by users. When an untrusted user is allowed to query readable collections through these dynamic filters or joins, the input is not properly sanitized before being incorporated into SQL statements. This allows an attacker to inject arbitrary SQL code, potentially leading to unauthorized data disclosure, data manipulation, or in some cases, complete database compromise. The vulnerability is particularly dangerous because it requires no authentication in certain configurations; any user who can query a readable collection can trigger it. The affected versions are all releases from 3.0.0 up to, but not including, 3.88.0, as well as the canary releases from 4.0.0-canary.0 up to, but not including, 4.0.0-canary.27. Users of MongoDB are explicitly not affected. The vulnerability was published on September 22, 2026, and a patch was released on October 6, 2026, in versions 3.88.0 and 4.0.0-canary.27. The CVSS score is 9.8, indicating a critical severity. The attack vector is network-based, requires low complexity, and needs no privileges or user interaction. The impact includes high confidentiality, integrity, and availability loss. Until the patch is applied, the recommended workaround is to restrict untrusted users from supplying dynamic query filters or join parameters and to limit read access to affected collections. This vulnerability underscores the importance of proper input sanitization and the risks associated with dynamic query construction in database-backed applications.
DailyCVE Form:
Platform: Payload CMS
Version: 3.0.0-3.88.0
Vulnerability: SQL Injection
Severity: Critical
date: Sep 22, 2026
Prediction: Oct 6, 2026
What Undercode Say:
Check if your Payload version is affected npm list payload Upgrade to a patched version npm install [email protected] or for canary npm install [email protected]
// Example of vulnerable dynamic filter usage (do not use in production)
const query = {
where: {
field: {
equals: userInput
}
}
};
Exploit: (Educational Purposes!)
POST /api/collection/query
Content-Type: application/json
{
"where": {
"id": {
"equals": "1' OR '1'='1"
}
}
}
Protection: from this CVE
- Upgrade Payload packages to >= 3.88.0 or >= 4.0.0-canary.27.
- Restrict untrusted users from supplying dynamic query filters or join parameters.
- Limit read access to affected collections.
- Use MongoDB (@payloadcms/mongodb) if feasible.
Impact:
Successful exploitation allows an attacker to execute arbitrary SQL queries, potentially leading to unauthorized data access, data modification, or deletion. In severe cases, the attacker may gain full control over the database, compromising the confidentiality, integrity, and availability of the application’s data.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

