Vulnerability in Payload CMS Affects Password Recovery Flow
CVE-2026-34751
9.1CRITICAL
What is CVE-2026-34751?
A security flaw exists in the password recovery mechanism of Payload CMS and its @payloadcms/graphql component, which could allow an unauthorized attacker to execute actions on behalf of a legitimate user who triggers a password reset. This issue has been addressed in the 3.79.1 update, ensuring secure handling of user recovery processes.
Affected Version(s)
payload < 3.79.1
