Security Flaw in Cloudinary Plugin for Payload CMS Exposes User Data
CVE-2026-58200

7.1HIGH

Key Information:

Vendor
CVE Published:
15 September 2026

What is CVE-2026-58200?

The Payload Cloudinary Plugin versions 0.3.0 to 0.4.0 has a significant security flaw that allows authenticated users to exploit the POST /api/cloudinary-generate-signature endpoint. This endpoint processes user-input parameters without proper validation, enabling attackers to generate valid Cloudinary HMAC-SHA1 signatures. Such unauthorized signatures can grant access to critical operations, including asset replacements and uploads, thereby jeopardizing the integrity of the system and exposing sensitive user data. This vulnerability was corrected in version 0.4.0 of the plugin.

Affected Version(s)

payload-plugins >= 0.3.0, < 0.4.0

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.