Token Exposure in Payload CMS from Unauthorized Access and Data Reveal
CVE-2026-105853

7.1HIGH

Key Information:

Vendor

Payloadcms

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-105853?

The Payload CMS is prone to a data exposure vulnerability where token refresh and password reset requests may leak hidden or read-restricted fields to users without appropriate permissions. This flaw occurs in versions 3.0.0 through 3.89.9, as well as in certain canary builds prior to version 4.0.0-canary.34. The vulnerability is resolved in version 3.90.0 and later. It is essential for users running affected versions to upgrade promptly to mitigate risks associated with unauthorized data exposure.

Affected Version(s)

payload >= 3.0.0, < 3.90.0 < 3.0.0, 3.90.0

payload >= 4.0.0-canary.0, < 4.0.0-canary.34 < 4.0.0-canary.0, 4.0.0-canary.34

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.