CVE-2026-105847: Information Disclosure via Polymorphic Join Queries in Payload CMS
Vulnerability ID: CVE-2026-105847
CVSS Score: 7.1
Published: 2026-10-06
Payload CMS is subject to an information disclosure vulnerability where users with query permissions can bypass field-level access controls. By leveraging polymorphic join filters, an attacker can perform blind-inference queries to retrieve restricted or hidden fields such as password reset tokens.
TL;DR
A validation bypass in Payload CMS's polymorphic join filters allows authenticated users to query and infer the values of hidden or restricted fields.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-200, CWE-639
- Attack Vector: Network (AV:N)
- CVSS Score: 7.1 (High)
- EPSS Score: N/A
- Impact: Information Disclosure / Privilege Escalation
- Exploit Status: Proof-of-Concept / Test-Suite Level
- KEV Status: Not Listed
Affected Systems
- Payload CMS
-
payload: >= 3.0.0, < 3.90.0 (Fixed in:
3.90.0) -
payload: >= 4.0.0-canary.0, < 4.0.0-canary.34 (Fixed in:
4.0.0-canary.34)
Code Analysis
Commit: caa3f69
Fix: polymorphic join query validation bypass on hidden/restricted fields
Exploit Details
- Official Integration Test: The official test suite includes tests validating rejection of hidden/restricted fields within polymorphic joins.
Mitigation Strategies
- Upgrade Payload CMS to version 3.90.0 or later.
- Upgrade Payload CMS 4.x canary to 4.0.0-canary.34 or later.
- Disable or restrict polymorphic joins using beforeOperation hooks.
- Deploy WAF rules to inspect and sanitize polymorphic join parameters.
Remediation Steps:
- Identify all instances of the payload package in package.json.
- Update the package version to ^3.90.0 or newer.
- Run package manager update command (e.g., npm install or pnpm update).
- Verify that polymorphic joins to restricted fields are rejected with a 400 Bad Request.
References
- GitHub Fix Commit
- GitHub Security Advisory (GHSA-fpww-c55p-cjv6)
- Payload CMS v3.90.0 Release Notes
- NVD Security Reference
Read the full report for CVE-2026-105847 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)