Description
SQLAdmin is a flexible Admin interface for SQLAlchemy models. Prior to 0.27.1, ModelView.sort_query in sqladmin/models.py accepts the attacker-controlled sortBy list-view query parameter without enforcing the configured column_sortable_list server-side allow-list in self._sort_fields. The value is resolved with getattr and passed to relationship joins and order_by, allowing requests to sort by columns hidden from column_list and by related-model columns through dotted paths. The resulting row order forms an information-exposure oracle for unexposed values, and reversing ascending and descending order confirms their relative ordering. Pairing sortBy with searchable or filterable columns and pagination can narrow the oracle toward specific values, but exact recovery depends on the application's available fields and data. This issue is fixed in version 0.27.1.
Published: 2026-09-14
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Patch
AI Analysis

Impact

SQLAdmin is a flexible Admin interface for SQLAlchemy models. Prior to 0.27.1, ModelView.sort_query in sqladmin/models.py accepts the attacker‑controlled sortBy list‑view query parameter without enforcing the configured column_sortable_list server‑side allow‑list in self._sort_fields. The value is resolved with getattr and passed to relationship joins and order_by, allowing requests to sort by columns hidden from column_list and by related‑model columns through dotted paths. The resulting row order forms an information‑exposure oracle for unexposed values, and reversing ascending and descending order confirms their relative ordering. Pairing sortBy with searchable or filterable columns and pagination can narrow the oracle toward specific values, but exact recovery depends on the application’s available fields and data.

Affected Systems

Deployments of smithyhq SQLAdmin version 0.27.0 or earlier (i.e., any release prior to 0.27.1) are affected. Instances that use ModelView with the default sorting logic and rely on the framework's column_sortable_list configuration are vulnerable. The issue was resolved in the 0.27.1 release and subsequent versions.

Risk and Exploitability

The vulnerability is rated moderate with a CVSS score of 5.3, indicating that exploitation is feasible without privileged access. The EPSS score of 0.00378 (<1%) suggests a very low but nonzero likelihood of exploitation, and the flaw is not listed in CISA's KEV catalog. Based on the description, it is inferred that attackers could remotely exploit the flaw over HTTP by crafting sortBy parameters in browser or API requests that target the admin interface. The vulnerability does not grant code execution or privilege escalation but can expose sensitive database values that may be leveraged in further attacks.

Generated by OpenCVE AI on September 21, 2026 at 00:33 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade SQLAdmin to version 0.27.1 or later to receive the official patch that validates the sortBy parameter against the column_sortable_list allow‑list.
  • If an immediate upgrade is not feasible, modify each ModelView to explicitly whitelist sortable columns, ensuring that only intended columns can be used for ordering.
  • Audit any custom overrides of ModelView.sort_query to verify that they enforce the column_sortable_list or otherwise limit the sortBy input, preventing exposure of hidden or related columns.

Generated by OpenCVE AI on September 21, 2026 at 00:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-ccg5-9c8w-xh6v SQLAdmin: Unvalidated sortBy parameter in `ModelView` bypasses `column_sortable_list`
History

Tue, 15 Sep 2026 05:15:00 +0000

Type Values Removed Values Added
First Time appeared Smithyhq
Smithyhq sqladmin
Vendors & Products Smithyhq
Smithyhq sqladmin

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description SQLAdmin is a flexible Admin interface for SQLAlchemy models. Prior to 0.27.1, ModelView.sort_query in sqladmin/models.py accepts the attacker-controlled sortBy list-view query parameter without enforcing the configured column_sortable_list server-side allow-list in self._sort_fields. The value is resolved with getattr and passed to relationship joins and order_by, allowing requests to sort by columns hidden from column_list and by related-model columns through dotted paths. The resulting row order forms an information-exposure oracle for unexposed values, and reversing ascending and descending order confirms their relative ordering. Pairing sortBy with searchable or filterable columns and pagination can narrow the oracle toward specific values, but exact recovery depends on the application's available fields and data. This issue is fixed in version 0.27.1.
Title SQLAdmin: Unvalidated sortBy parameter in `ModelView` bypasses `column_sortable_list`
Weaknesses CWE-20
CWE-200
CWE-248
CWE-639
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Smithyhq Sqladmin
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-14T16:29:44.765Z

Reserved: 2026-06-15T18:40:01.651Z

Link: CVE-2026-54529

cve-icon Vulnrichment

Updated: 2026-09-14T16:29:40.077Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T16:17:12.050

Modified: 2026-09-30T19:38:27.293

Link: CVE-2026-54529

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T00:45:08Z

Weaknesses
  • CWE-20

    Improper Input Validation

  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-248

    Uncaught Exception

  • CWE-639

    Authorization Bypass Through User-Controlled Key