Payload CMS, Information Disclosure, CVE-2026-105853 (High) -DC-Oct2026-2766

Listen to this Post

Payload is a free and open source headless content management system.
In versions from 3.0.0 before 3.90.0 and canary versions before 4.0.0-canary.34,
token refresh responses and password reset responses can independently return
hidden or read-restricted fields that the requesting user cannot access.
This occurs because authentication responses did not apply field-level access

control or hidden-field filtering before returning user documents.

An authentication collection may define fields with hidden: true or

access: { read: … } restrictions.

When a user refreshes their token or resets their password,
the server returns the full user document including those restricted fields.
An attacker with a low-privileged account can trigger these endpoints
and receive sensitive data such as password hashes, reset tokens,

or other private fields.

The vulnerability is classified as CWE-200: Exposure of Sensitive Information

to an Unauthorized Actor.

The CVSS v4.0 base score is 7.1, rated as High severity.

Attack vector is Network, attack complexity is Low,

privileges required are Low, and no user interaction is needed.
The issue is fixed in versions 3.90.0 and 4.0.0-canary.34.

Patches now apply field access and hidden-field filtering

before returning user documents in authentication responses.

Full user documents remain available server-side for access control.

Custom authentication strategies remain responsible for filtering

user documents returned through custom responses.

There is no complete workaround; users must upgrade.

The vulnerability was published on 2026-09-18 and reviewed on 2026-10-06.

It affects the payload package on npm.

The advisory is GHSA-xgv3-crq2-6f69.

This information disclosure can lead to further attacks

such as account takeover if reset tokens are exposed.

DailyCVE Form:

Platform: Payload
Version: 3.0.0-3.89.0
Vulnerability: Information Disclosure
Severity: High
date: 2026-09-18

Prediction: 2026-09-18

What Undercode Say:

Analytics

Check installed Payload version
npm list payload
or
cat package.json | grep '"payload"'
Test token refresh endpoint
curl -X POST https://example.com/api/users/refresh-token \
-H "Authorization: Bearer <user_token>" \
-H "Content-Type: application/json"
Test password reset endpoint
curl -X POST https://example.com/api/users/forgot-password \
-H "Content-Type: application/json" \
-d '{"email":"[email protected]"}'
// Payload local API example (server-side) that bypasses field access
const user = await payload.findByID({
collection: 'users',
id: userId,
overrideAccess: true, // returns all fields
});
console.log(user);

How Exploit: (Educational Purposes!)

An attacker with a valid low-privileged account can call the refresh token
or password reset endpoints. The response may include fields that are
normally hidden or read-restricted. By inspecting the JSON response,

the attacker can extract sensitive information.

Protection: from this CVE

Upgrade Payload to version 3.90.0 or later, or 4.0.0-canary.34 or later.

Apply field-level access control and hidden-field filtering

in custom authentication strategies.

Monitor for unusual token refresh or password reset requests.

Impact:

Token refresh and password reset responses could return fields
that the requesting user did not have access to.

This leads to exposure of sensitive user data,

potentially enabling account takeover or privilege escalation.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top