Payload, Field Access Control Bypass, CVE-2026-105851 (Critical) -DC-Oct2026-2768

Listen to this Post

CVE-2026-105851 is a critical improper access control vulnerability (CWE-284) affecting Payload CMS, a free and open source headless content management system. The flaw resides in the duplicate operation, a core feature that allows users to create a copy of an existing document. When duplicating a document, Payload copies field values from the source document to the new one. However, the vulnerability causes the system to copy these values even when the field is hidden or when the field’s `access.read` or `access.create` rules would normally reject that value for the caller. This means that an authenticated user with low privileges can potentially access and duplicate sensitive field data that they are not authorized to view or create. The `disableDuplicate` collection setting, which is enabled by default on auth collections to prevent duplication, does not stop this access-control bypass, as the underlying copy operation still proceeds. The vulnerability has a CVSS 4.0 score of 9.3, reflecting a network attack vector, low attack complexity, no privileges required, and high impact on confidentiality and integrity. The issue is fixed in Payload versions 3.90.0 and 4.0.0-canary.34, where access control rules are properly evaluated during field copying operations. Until an upgrade can be performed, a workaround involves adding a `beforeDuplicate` field hook to affected fields to set the value to empty or a default value. This vulnerability was published on September 18, 2026, and was reviewed by GitHub on October 6, 2026.

DailyCVE Form:

Platform: Payload CMS
Version: 3.0.0-3.90.0
Vulnerability: Access control bypass
Severity: Critical
date: Sep 18, 2026

Prediction: Oct 2026

What Undercode Say:

Check current Payload version
npm list payload
Upgrade to patched version
npm install [email protected]
For canary users
npm install [email protected]
// Workaround: Add beforeDuplicate hook to fields
const MyField: Field = {
name: 'sensitiveField',
type: 'text',
hooks: {
beforeDuplicate: [
({ value }) => {
// Set value to empty or default
return '';
},
],
},
};

Exploit: (Educational Purposes!)

An authenticated user can trigger the duplicate operation on a document they have access to. The duplicate operation will copy field values from the source document, including those the user is not authorized to read or create, because the access control rules are not properly evaluated during the duplication process. The user can then access the newly created document to view the leaked field values.

Protection: from this CVE

Upgrade Payload packages to version 3.90.0 or later, or 4.0.0-canary.34 or later. If an immediate upgrade is not possible, add a `beforeDuplicate` field hook to sensitive fields and set the value to empty or your default value.

Impact:

Successful exploitation allows an authenticated attacker to bypass field-level access controls and gain unauthorized read and create access to sensitive data stored in fields on auth collections. This can lead to information disclosure and potential data integrity issues.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top