Authentication Bypass in Payload Plugins by jhb.software
CVE-2026-59965
7.1HIGH
What is CVE-2026-59965?
Payload Plugins for Payload CMS contains a vulnerability where the @jhb.software/payload-alt-text-plugin improperly authorizes authenticated users via exposed API endpoints. The endpoints allow low-privileged users to read and modify protected upload documents by invoking operations typically restricted to administrators. This Security flaw stems from the default configuration that skips rigorous access checks, facilitating unauthorized alterations to critical fields, such as alt-text and keywords. The issue has been addressed in version 0.8.0 of the plugin, mitigating the risk of potential data breaches.
Affected Version(s)
payload-alt-text-plugin < 0.8.0
payload-plugins < 0.8.0
