CVE-2026-105855: Privilege Escalation via Improper Access Control on Password Fields in Payload CMS
Vulnerability ID: CVE-2026-105855
CVSS Score: 7.6
Published: 2026-10-06
An Improper Access Control vulnerability (CWE-284) in Payload CMS prior to version 3.90.0 and 4.0.0-canary.34 allows authenticated, low-privileged users to bypass field-level access control restrictions and overwrite the password of other accounts, leading to complete account takeover and privilege escalation.
TL;DR
An authentication bypass and privilege escalation vulnerability in Payload CMS allows authenticated users to overwrite the passwords of other accounts, including administrators, due to premature password extraction prior to access control validation.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-284
- Attack Vector: Network (AV:N)
- CVSS v4.0 Score: 7.6 (High)
- EPSS Score: Not Available
- Exploit Status: poc
- KEV Status: Not Listed
Affected Systems
- Payload CMS
-
payload: < 3.90.0 (Fixed in:
3.90.0) -
payload: >= 4.0.0-canary.0 < 4.0.0-canary.34 (Fixed in:
4.0.0-canary.34)
Code Analysis
Commit: 9de9e79
Fix field access.update bypass on password fields
Mitigation Strategies
- Upgrade Payload CMS to a patched version (v3.90.0+ or v4.0.0-canary.34+)
- Monitor API traffic for unauthorized PATCH/PUT requests targeting authentication endpoints
- Audit collection access control configurations
Remediation Steps:
- Open the project package.json file.
- Update the 'payload' dependency to '3.90.0' or newer (or '4.0.0-canary.34' or newer for canary users).
- Run the package manager install command (e.g., npm install, yarn install, or pnpm install).
- Verify the installed version in package-lock.json or yarn.lock.
- Deploy the updated application to production environments.
References
- Payload CMS Security Advisory GHSA-fx49-4h83-wjv9
- Patch Commit 9de9e7911e29d60870a1d5480412524c63d6411e
- Payload CMS v3.90.0 Release Notes
Read the full report for CVE-2026-105855 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)