CVE-2026-105845

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Payload is a free and open source headless content management system. In versions from 3.0.0 before 3.88.0 and canary versions before 4.0.0-canary.27, an untrusted user who can query readable collections through dynamic filters or joins can submit a request that causes SQL injection in the SQLite and Postgres adapters. This issue is fixed in versions 3.88.0 and 4.0.0-canary.27.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-06: 110-06
Full discourse1 post
  • Upwind Security MDR@UpwindMDR

    🚨Critical - Payload CMS SQL Injection via Dynamic Filters/Joins (CVE-2026-105845) Payload headless CMS SQL injection in the SQLite and Postgres adapters when building queries from dynamic filters/joins on readable collections. Untrusted users can craft filter/join params to inject SQL, enabling data exfiltration and DB tampering. Other adapters are not affected. 👉Affected: payload < 3.88.0 | Upgrade to 3.88.0

    0000053
    311 followersView on X

Explore more