Token Exposure in Payload CMS from Unauthorized Access and Data Reveal
CVE-2026-105853
7.1HIGH
What is CVE-2026-105853?
The Payload CMS is prone to a data exposure vulnerability where token refresh and password reset requests may leak hidden or read-restricted fields to users without appropriate permissions. This flaw occurs in versions 3.0.0 through 3.89.9, as well as in certain canary builds prior to version 4.0.0-canary.34. The vulnerability is resolved in version 3.90.0 and later. It is essential for users running affected versions to upgrade promptly to mitigate risks associated with unauthorized data exposure.
Affected Version(s)
payload >= 3.0.0, < 3.90.0 < 3.0.0, 3.90.0
payload >= 4.0.0-canary.0, < 4.0.0-canary.34 < 4.0.0-canary.0, 4.0.0-canary.34
