Payload CMS SQL Injection (CVE-2026-105845) Critical -DC-Oct2026-2763

Listen to this Post

CVE-2026-105845 is a critical SQL injection vulnerability affecting the Payload CMS (payloadcms/payload) when used with SQLite or Postgres adapters. The flaw resides in the handling of dynamic query filters and join parameters supplied by users. When an untrusted user is allowed to query readable collections through these dynamic filters or joins, the input is not properly sanitized before being incorporated into SQL statements. This allows an attacker to inject arbitrary SQL code, potentially leading to unauthorized data disclosure, data manipulation, or in some cases, complete database compromise. The vulnerability is particularly dangerous because it requires no authentication in certain configurations; any user who can query a readable collection can trigger it. The affected versions are all releases from 3.0.0 up to, but not including, 3.88.0, as well as the canary releases from 4.0.0-canary.0 up to, but not including, 4.0.0-canary.27. Users of MongoDB are explicitly not affected. The vulnerability was published on September 22, 2026, and a patch was released on October 6, 2026, in versions 3.88.0 and 4.0.0-canary.27. The CVSS score is 9.8, indicating a critical severity. The attack vector is network-based, requires low complexity, and needs no privileges or user interaction. The impact includes high confidentiality, integrity, and availability loss. Until the patch is applied, the recommended workaround is to restrict untrusted users from supplying dynamic query filters or join parameters and to limit read access to affected collections. This vulnerability underscores the importance of proper input sanitization and the risks associated with dynamic query construction in database-backed applications.

DailyCVE Form:

Platform: Payload CMS
Version: 3.0.0-3.88.0
Vulnerability: SQL Injection
Severity: Critical
date: Sep 22, 2026

Prediction: Oct 6, 2026

What Undercode Say:

Check if your Payload version is affected
npm list payload
Upgrade to a patched version
npm install [email protected]
or for canary
npm install [email protected]
// Example of vulnerable dynamic filter usage (do not use in production)
const query = {
where: {
field: {
equals: userInput
}
}
};

Exploit: (Educational Purposes!)

POST /api/collection/query
Content-Type: application/json
{
"where": {
"id": {
"equals": "1' OR '1'='1"
}
}
}

Protection: from this CVE

  • Upgrade Payload packages to >= 3.88.0 or >= 4.0.0-canary.27.
  • Restrict untrusted users from supplying dynamic query filters or join parameters.
  • Limit read access to affected collections.
  • Use MongoDB (@payloadcms/mongodb) if feasible.

Impact:

Successful exploitation allows an attacker to execute arbitrary SQL queries, potentially leading to unauthorized data access, data modification, or deletion. In severe cases, the attacker may gain full control over the database, compromising the confidentiality, integrity, and availability of the application’s data.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top