Authentication Bypass in Payload Plugins by jhb.software
CVE-2026-59965

7.1HIGH

Key Information:

Vendor
CVE Published:
15 September 2026

What is CVE-2026-59965?

Payload Plugins for Payload CMS contains a vulnerability where the @jhb.software/payload-alt-text-plugin improperly authorizes authenticated users via exposed API endpoints. The endpoints allow low-privileged users to read and modify protected upload documents by invoking operations typically restricted to administrators. This Security flaw stems from the default configuration that skips rigorous access checks, facilitating unauthorized alterations to critical fields, such as alt-text and keywords. The issue has been addressed in version 0.8.0 of the plugin, mitigating the risk of potential data breaches.

Affected Version(s)

payload-alt-text-plugin < 0.8.0

payload-plugins < 0.8.0

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.