DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-105847: CVE-2026-105847: Information Disclosure via Polymorphic Join Queries in Payload CMS

CVE-2026-105847: Information Disclosure via Polymorphic Join Queries in Payload CMS

Vulnerability ID: CVE-2026-105847
CVSS Score: 7.1
Published: 2026-10-06

Payload CMS is subject to an information disclosure vulnerability where users with query permissions can bypass field-level access controls. By leveraging polymorphic join filters, an attacker can perform blind-inference queries to retrieve restricted or hidden fields such as password reset tokens.

TL;DR

A validation bypass in Payload CMS's polymorphic join filters allows authenticated users to query and infer the values of hidden or restricted fields.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-200, CWE-639
  • Attack Vector: Network (AV:N)
  • CVSS Score: 7.1 (High)
  • EPSS Score: N/A
  • Impact: Information Disclosure / Privilege Escalation
  • Exploit Status: Proof-of-Concept / Test-Suite Level
  • KEV Status: Not Listed

Affected Systems

  • Payload CMS
  • payload: >= 3.0.0, < 3.90.0 (Fixed in: 3.90.0)
  • payload: >= 4.0.0-canary.0, < 4.0.0-canary.34 (Fixed in: 4.0.0-canary.34)

Code Analysis

Commit: caa3f69

Fix: polymorphic join query validation bypass on hidden/restricted fields

Exploit Details

  • Official Integration Test: The official test suite includes tests validating rejection of hidden/restricted fields within polymorphic joins.

Mitigation Strategies

  • Upgrade Payload CMS to version 3.90.0 or later.
  • Upgrade Payload CMS 4.x canary to 4.0.0-canary.34 or later.
  • Disable or restrict polymorphic joins using beforeOperation hooks.
  • Deploy WAF rules to inspect and sanitize polymorphic join parameters.

Remediation Steps:

  1. Identify all instances of the payload package in package.json.
  2. Update the package version to ^3.90.0 or newer.
  3. Run package manager update command (e.g., npm install or pnpm update).
  4. Verify that polymorphic joins to restricted fields are rejected with a 400 Bad Request.

References


Read the full report for CVE-2026-105847 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)