Elide through 7.1.17 fails to enforce @ReadPermission on client-supplied sort expressions in SortingImpl.getValidSortingRules, allowing attackers to sort collections by forbidden fields. Attackers can infer hidden field values through row ordering analysis, leaking relative field ordering across all rows via both JSON:API and GraphQL read paths.
Metrics
Affected Vendors & Products
References
History
Mon, 29 Jun 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Elide through 7.1.17 fails to enforce @ReadPermission on client-supplied sort expressions in SortingImpl.getValidSortingRules, allowing attackers to sort collections by forbidden fields. Attackers can infer hidden field values through row ordering analysis, leaking relative field ordering across all rows via both JSON:API and GraphQL read paths. | |
| Title | Elide 7.1.17 - Permission Bypass in Sort Expression Validation | |
| First Time appeared |
Elide
Elide elide |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:elide:elide:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Elide
Elide elide |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-29T17:21:55.510Z
Reserved: 2026-06-26T13:59:33.048Z
Link: CVE-2026-57954
No data.
No data.
No data.
OpenCVE Enrichment
No data.