External risk intelligence

Payload SQL Injection Vulnerability Affects SQLite and Postgres Adapters

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-105845

Payload is a content management system typically deployed as an internet-facing web application. Since it serves as a web-accessible platform for managing content, its collections and query interfaces are commonly exposed to the public internet to facilitate site functionality.

SQL Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a critical vulnerability in Payload, an open-source content management system, that could allow unauthorized users to execute malicious code through specially crafted requests. The issue stems from SQL injection vulnerabilities within its SQLite and Postgres adapters, potentially impacting data integrity and system availability. Confirmation of affected systems is the primary concern.

  • Malicious input could compromise content management systems.
  • Remote attackers may execute commands.
  • Verify if your content management system is exposed.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this by sending specially crafted requests to a Payload CMS application. If the application uses dynamic filters or joins on readable collections, these requests can inject malicious SQL commands. This could allow an attacker to manipulate or steal data.

  • Unauthenticated access to query collections.
  • Submitting requests with dynamic filters/joins.
  • SQL injection leading to data compromise.

Live Threat

Current exploitation, exposure, and threat context

An untrusted user could exploit this vulnerability to inject malicious SQL code into the system through dynamic filters or joins when querying readable collections. This could impact the integrity and availability of data within the SQLite and Postgres databases.

  • Affects database integrity and availability.
  • SQL injection via dynamic queries.
  • Potential data corruption or denial of service.

Operational Fix

Recommended remediation, mitigation, and detection steps

This SQL injection vulnerability in Payload, affecting SQLite and Postgres adapters, impacts application owners responsible for the content management system and its deployed instances. The initial focus should be on identifying all deployments, assessing their reachability and criticality, and then pinpointing the accountable owner to plan remediation.

  • Application owners to manage issue.
  • Verify external reachability and criticality.
  • Plan coordinated updates or risk mitigation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Payload CMS?

Payload is a free, open-source headless content management system (CMS). Developers use it to build and manage structured content for websites and applications. Being headless, it provides an API-first approach, allowing teams to manage data that is then delivered to any frontend, typically via database adapters like SQLite or Postgres.

How does CVE-2026-105845 cause a security risk?

This vulnerability is classified as Improper Neutralization of Special Elements used in an SQL Command (CWE-89). It occurs when the application fails to properly sanitize user input in dynamic filters or joins. Because of this, a malicious request can manipulate the underlying database queries, potentially allowing an attacker to read, modify, or delete information.

Do I need to be an authenticated user to trigger this bug?

No, you do not need to be authenticated to trigger this vulnerability. The issue arises when an untrusted user submits a specially crafted request that utilizes dynamic filters or joins on readable collections. Simply querying public or accessible collections in a way that includes these crafted parameters is sufficient to trigger the SQL injection; it does not require administrative privileges.

Is my Payload instance at high risk?

Halo Surface Signal notes that Payload is commonly deployed as an internet-facing web application to support site functionality, which increases the likelihood of exposure. If your instance is accessible from the public internet, it is reachable by remote actors. Internal-only instances still face risk if malicious actors gain access to your private network.

How do I secure my application against this vulnerability?

Your first step is to identify all running instances of Payload CMS to determine which are reachable. Once identified, upgrade your software to version 3.88.0 or 4.0.0-canary.27, as these releases contain the necessary fixes for the SQLite and Postgres adapters. Prioritize these updates for any instances that are exposed to the public internet.

References