Elide through 7.1.17 fails to enforce @ReadPermission on client-supplied sort expressions in SortingImpl.getValidSortingRules, allowing attackers to sort collections by forbidden fields. Attackers can infer hidden field values through row ordering analysis, leaking relative field ordering across all rows via both JSON:API and GraphQL read paths.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 29 Jun 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Elide through 7.1.17 fails to enforce @ReadPermission on client-supplied sort expressions in SortingImpl.getValidSortingRules, allowing attackers to sort collections by forbidden fields. Attackers can infer hidden field values through row ordering analysis, leaking relative field ordering across all rows via both JSON:API and GraphQL read paths. | |
| Title | Elide 7.1.17 - Permission Bypass in Sort Expression Validation | |
| First Time appeared |
Elide
Elide elide |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:elide:elide:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Elide
Elide elide |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-29T17:21:55.510Z
Reserved: 2026-06-26T13:59:33.048Z
Link: CVE-2026-57954
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-29T20:00:03Z
Weaknesses