SQL Injection Vulnerability in Payload CMS by Payload
CVE-2026-105845
9.8CRITICAL
What is CVE-2026-105845?
A vulnerability exists in Payload CMS where an untrusted user can exploit SQL injection through dynamic filters or joins when querying readable collections. This affects versions 3.0.0 up to 3.87.9 and canary versions before 4.0.0-canary.27. Successful exploitation can lead to unauthorized access to sensitive data or manipulation of database contents. The issue is addressed in versions 3.88.0 and 4.0.0-canary.27. It is crucial for users to update their systems to mitigate the risks associated with this vulnerability.
Affected Version(s)
payload >= 3.0.0, < 3.88.0 < 3.0.0, 3.88.0
payload >= 4.0.0-canary.0, < 4.0.0-canary.27 < 4.0.0-canary.0, 4.0.0-canary.27
