PT-2026-106767 · Pyload · Pyload
CVE-2026-105805
·
Published
2026-10-06
·
Updated
2026-10-06
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Payload versions prior to 3.88.0
Payload canary versions prior to 4.0.0-canary.27
Description
An untrusted user can infer limited information about protected field values they are not permitted to read. This occurs when a user can query a readable collection and control the sorting by selecting a protected field as the sort parameter.
Recommendations
Update to version 3.88.0 or later.
Update to canary version 4.0.0-canary.27 or later.
Prevent untrusted users from controlling sort parameters.
Restrict user access to affected collections.
Exploit
Fix
Information Disclosure
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pyload