Listen to this Post
CVE-2026-105852 is a missing authorization vulnerability in Payload CMS, a free and open-source headless content management system. The flaw resides in the handling of relationship queries, specifically when a publicly readable collection contains a relationship field pointing to a protected collection. Under normal circumstances, access to documents in the protected collection is governed by access.read where constraints, which should prevent unauthorized users from reading those documents. However, the vulnerability allows an unauthenticated attacker to bypass these constraints by crafting nested query parameters on the public collection. By querying the public collection and including a filter on the related protected field, the attacker can infer the existence and metadata of restricted documents. This occurs because the query engine processes the relationship join without properly authorizing the request against the owning protected object using the caller’s authentication context. The flaw affects both MongoDB and Drizzle SQL database adapters, meaning it is not limited to a single database backend. The attack vector is network-based, and the complexity is low, as no special privileges or user interaction are required. The vulnerability is classified as CWE-862 (Missing Authorization) and has a CVSS v4.0 score of 5.3, placing it in the moderate severity range. Exploitation does not directly expose the full contents of protected documents, but it acts as a related-document oracle, leaking metadata and confirming document existence. This information disclosure can be leveraged for further targeted attacks, such as mapping out the structure of restricted data or identifying valid document identifiers. The issue was addressed in commit 94059cf, which ensures that the $relatedTo operator authorizes against the owning object before reading the relation join table. Users are affected if they expose a readable collection with a relationship to a collection protected by access.read where constraints. There is no complete workaround other than upgrading. The patched versions are 3.90.0 for the stable release and 4.0.0-canary.34 for the canary release. The vulnerability was published on September 18, 2026, and the patches were released on October 6, 2026. Given the moderate severity and the availability of patches, immediate upgrading is recommended for all affected deployments. The lack of authentication requirements makes this a particularly dangerous issue for any publicly accessible Payload instance. Administrators should audit their schemas for nested relationship queries and ensure that field-level access controls are strictly enforced.
DailyCVE Form:
Platform: Payload CMS
Version: < 3.90.0, 4.0.0-canary.0–33
Vulnerability: Auth Bypass
Severity: Moderate
date: 2026-09-18
Prediction: 2026-10-06
What Undercode Say:
Check current Payload version npm list payload Upgrade to patched version npm install [email protected] For canary users npm install [email protected]
Example vulnerable request (GraphQL)
curl -X POST https://example.com/api/graphql \
-H "Content-Type: application/json" \
-d '{"query":"query { PublicCollection(where: { relatedField: { equals: \"target-id\" } }) { docs { id } } }"}'
Exploit: (Educational Purposes!)
query {
PublicCollection(
where: {
relatedField: {
equals: "restricted-document-id"
}
}
) {
docs {
id
relatedField
}
}
}
REST equivalent curl "https://example.com/api/public-collection?where\[relatedField\]\[equals\]=restricted-document-id"
Protection: from this CVE
Upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34. Audit schemas for relationship, upload, or join fields pointing to restricted collections. Apply strict field-level access control policies on relations. Restrict querying capabilities on public collections that reference protected collections.
Impact:
A readable collection could expose information about protected documents in a related collection. Unauthenticated attackers can infer the existence and metadata of restricted documents, enabling related-document oracle attacks. This information disclosure can facilitate further targeted attacks by mapping restricted data structures.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

