CVE-2026-105805EPSS p18.5%
CVE-2026-105805CVE-2026-105805
Description
Payload is a free and open source headless content management system. In versions before 3.88.0 and canary versions before 4.0.0-canary.27, an untrusted user who can query a readable collection, control its sorting, and select a protected field as the sort parameter can infer limited information about field values the user cannot read. This issue is fixed in versions 3.88.0 and 4.0.0-canary.27.
Scoring
| EPSS | 0.28% probability of exploitation · percentile 18.5% · 2026-10-10T12:00:23Z |
| Last modified | 2026-10-06 |