Under certain conditions, sorting readable records could reveal limited information about fields the requester was not permitted to read.
You are affected if untrusted users can query a collection, control its sorting, and sort by protected fields.
Payload now applies field-level access checks to sort fields before executing queries.
Users should upgrade to >= 3.88.0 or >= 4.0.0-canary.27.
Upgrading is recommended. Until then, prevent untrusted users from controlling sort parameters or restrict their access to affected collections.
{
"cwe_ids": [
"CWE-200",
"CWE-863"
],
"github_reviewed": true,
"github_reviewed_at": "2026-10-06T15:38:32Z",
"nvd_published_at": null,
"severity": "MODERATE"
}