DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-105853: CVE-2026-105853: Sensitive Information Disclosure and Authentication Collection Boundary Bypass in Payload CMS

CVE-2026-105853: Sensitive Information Disclosure and Authentication Collection Boundary Bypass in Payload CMS

Vulnerability ID: CVE-2026-105853
CVSS Score: 7.1
Published: 2026-10-06

CVE-2026-105853 is a high-severity information disclosure vulnerability in Payload CMS that affects authentication-enabled collections. In vulnerable versions, the application fails to properly serialize and sanitize user documents during token refresh and password reset operations. This deficiency leaks hidden and read-restricted fields to unauthorized actors. Additionally, a logical flaw in token refresh validation allows low-privileged users to cross collection boundaries, exposing sensitive configuration details and administrative metadata.

TL;DR

Payload CMS fails to sanitize user documents in password reset and token refresh endpoints, allowing low-privileged authenticated users to access hidden or read-restricted fields across collection boundaries.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-200
  • Attack Vector: Network (AV:N)
  • CVSS v4.0 Score: 7.1
  • EPSS Score: Not yet populated
  • Impact: High Confidentiality Exposure
  • Exploit Status: poc
  • KEV Status: No

Affected Systems

  • Payload CMS installations with multiple authentication-enabled collections
  • Payload CMS installations with custom fields marked as hidden
  • payload: >= 3.0.0, < 3.90.0 (Fixed in: 3.90.0)
  • payload: >= 4.0.0-canary.0, < 4.0.0-canary.34 (Fixed in: 4.0.0-canary.34)

Code Analysis

Commit: f5f1283

Fix token refresh collection boundary verification check

Mitigation Strategies

  • Upgrade Payload CMS dependencies to versions that contain the official security patches.
  • Manually review and sanitize user documents returned by custom authentication handlers.
  • Deploy WAF rules to monitor and block cross-collection token refresh requests.

Remediation Steps:

  1. Identify the current version of Payload CMS running in the package.json file.
  2. Upgrade the package to version 3.90.0 or higher for 3.x branches, or version 4.0.0-canary.34 or higher for 4.x branches.
  3. Rebuild and redeploy the application.
  4. Inspect custom authentication strategies and ensure they apply appropriate sanitization wrappers.

References


Read the full report for CVE-2026-105853 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)