PT-2026-53672 · Elide · Elide

·

CVE-2026-57954

·

Published

2026-06-29

·

Updated

2026-06-30

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Elide versions prior to 7.1.18
Description Insufficient enforcement of @ReadPermission within the getValidSortingRules() function of SortingImpl allows attackers to use forbidden fields in client-supplied sort expressions. By analyzing the resulting row ordering, attackers can infer the values of hidden fields and leak relative field ordering across all rows via JSON:API and GraphQL read paths.
Recommendations Update to version 7.1.18 or later.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-57954

Affected Products

Elide