Information Exposure in Payload CMS Versions Prior to 3.90.0
CVE-2026-105852
6.9MEDIUM
What is CVE-2026-105852?
A vulnerability exists in Payload CMS that may allow users to query a readable collection with connections to other collections, potentially revealing sensitive information about related documents that should be protected under access controls. Versions prior to 3.90.0 and canary releases before 4.0.0-canary.34 are affected. This vulnerability has been addressed in updated versions, enhancing security by enforcing access restrictions.
Affected Version(s)
payload < 3.90.0 < 3.90.0
payload >= 4.0.0-canary.0, < 4.0.0-canary.34 < 4.0.0-canary.0, 4.0.0-canary.34
