CVE-2026-57954: Missing Authorization in yahoo elide
Elide through 7.1.17 fails to enforce @ReadPermission on client-supplied sort expressions in SortingImpl.getValidSortingRules, allowing attackers to sort collections by forbidden fields. Attackers can infer hidden field values through row ordering analysis, leaking relative field ordering across all rows via both JSON:API and GraphQL read paths.
AI Analysis
Technical Summary
CVE-2026-57954 describes a missing authorization enforcement in Yahoo Elide through version 7.1.17. Specifically, the @ReadPermission annotation is not enforced on client-supplied sort expressions in the SortingImpl.getValidSortingRules method. This flaw enables attackers to sort data collections by fields that are normally restricted, allowing them to infer hidden field values by analyzing the ordering of rows returned. Both JSON:API and GraphQL read interfaces are affected. No official remediation or patch information is provided in the available data.
Potential Impact
Attackers can bypass read permission restrictions on sorting fields, enabling them to infer sensitive information about hidden fields by analyzing the order of rows in query results. This leakage occurs across all rows and affects both JSON:API and GraphQL endpoints. The vulnerability does not allow direct data access but leaks relative ordering information, which may aid in further information disclosure or reconnaissance.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, consider restricting client-supplied sorting or implementing additional access controls on sorting parameters to prevent unauthorized field sorting.
CVE-2026-57954: Missing Authorization in yahoo elide
Description
Elide through 7.1.17 fails to enforce @ReadPermission on client-supplied sort expressions in SortingImpl.getValidSortingRules, allowing attackers to sort collections by forbidden fields. Attackers can infer hidden field values through row ordering analysis, leaking relative field ordering across all rows via both JSON:API and GraphQL read paths.
CVSS v4.0
Score 5.3medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-57954 describes a missing authorization enforcement in Yahoo Elide through version 7.1.17. Specifically, the @ReadPermission annotation is not enforced on client-supplied sort expressions in the SortingImpl.getValidSortingRules method. This flaw enables attackers to sort data collections by fields that are normally restricted, allowing them to infer hidden field values by analyzing the ordering of rows returned. Both JSON:API and GraphQL read interfaces are affected. No official remediation or patch information is provided in the available data.
Potential Impact
Attackers can bypass read permission restrictions on sorting fields, enabling them to infer sensitive information about hidden fields by analyzing the order of rows in query results. This leakage occurs across all rows and affects both JSON:API and GraphQL endpoints. The vulnerability does not allow direct data access but leaks relative ordering information, which may aid in further information disclosure or reconnaissance.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, consider restricting client-supplied sorting or implementing additional access controls on sorting parameters to prevent unauthorized field sorting.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-06-26T13:59:33.048Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a42b42827e9c7971940f86b
Added to database: 06/29/2026, 18:06:32 UTC
Last enriched: 07/06/2026, 22:27:16 UTC
Last updated: 08/13/2026, 00:41:13 UTC
Views: 89
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.