DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-105852: CVE-2026-105852: Authorization Bypass and Related-Document Oracle in Payload CMS

CVE-2026-105852: Authorization Bypass and Related-Document Oracle in Payload CMS

Vulnerability ID: CVE-2026-105852
CVSS Score: 5.3
Published: 2026-10-06

An authorization bypass vulnerability in Payload CMS enables unauthenticated attackers to query and infer the existence of restricted documents via nested relationship queries on public collections. This cross-document contamination flaw affects both MongoDB and Drizzle SQL database adapters, allowing unauthorized reads of relationship metadata.

TL;DR

Unauthenticated attackers can bypass read-access controls on restricted collections via nested query parameters on related public collections, leaking metadata and confirming document existence.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-862 (Missing Authorization)
  • Attack Vector: Network (AV:N)
  • CVSS v4.0 Score: 5.3 (Medium)
  • EPSS Score: Not Available
  • Impact: Information Disclosure / Related-Document Oracle
  • Exploit Status: Proof of Concept (PoC) documented in integration test suite
  • KEV Status: Not Listed

Affected Systems

  • Payload CMS (npm package: payload)
  • payload: < 3.90.0 (Fixed in: 3.90.0)
  • payload: >= 4.0.0-canary.0 < 4.0.0-canary.34 (Fixed in: 4.0.0-canary.34)

Code Analysis

Commit: 94059cf

fix: relationship-query authorization bypass / related-document oracle

Mitigation Strategies

  • Upgrade Payload CMS dependencies to versions 3.90.0 or 4.0.0-canary.34 and above.
  • Identify relationship, upload, or join fields pointing to restricted collections and restrict querying capabilities.
  • Apply strict field-level access control policies on relations to prevent unauthenticated field lookup.

Remediation Steps:

  1. Open the package configuration file (package.json) and verify all payload-related packages.
  2. Run 'npm install payload@latest' or equivalent to update dependency mappings.
  3. Audit application schemas for nested relationship queries and implement query validation layers.

References


Read the full report for CVE-2026-105852 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)