CVE-2026-105851: CVE-2026-105851: Privilege Escalation via Field Access Control Bypass in Payload CMS Duplication Mechanism
CVE-2026-105851: Privilege Escalation via Field Access Control Bypass in Payload CMS Duplication Mechanism Vulnerability ID: CVE-2026-105851 CVSS Score: 9.3 Published: 2026-10-06 A critical access control bypass vul
CVE-2026-105851: Privilege Escalation via Field Access Control Bypass in Payload CMS Duplication Mechanism
Vulnerability ID: CVE-2026-105851
CVSS Score: 9.3
Published: 2026-10-06
A critical access control bypass vulnerability (CVE-2026-105851) in Payload CMS allows authenticated users to bypass field-level access controls during document duplication. By duplicating high-privilege documents, such as administrator accounts, standard users can inherit sensitive fields (e.g., role configurations or API keys), leading to privilege escalation.
TL;DR
Payload CMS failed to enforce field-level access controls and the disableDuplicate configuration during document duplication, allowing standard users to duplicate administrator profiles and escalate their privileges.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-284 / CWE-863
- Attack Vector: Network (Unauthenticated or Low-Privileged Local Network/API Access)
- CVSS v4.0: 9.3 (Critical)
- EPSS Score: Not Available
- Impact: Privilege Escalation / Unauthorized Data Access
- Exploit Status: Conceptual / Proof-of-Concept
- CISA KEV Status: Not Listed
Affected Systems
- Payload CMS
-
payload: >= 3.0.0, < 3.90.0 (Fixed in:
3.90.0) -
payload: >= 4.0.0-canary.0, < 4.0.0-canary.34 (Fixed in:
4.0.0-canary.34)
Code Analysis
Commit: 099ef12
Field access control bypass on auth collections fix
Mitigation Strategies
- Upgrade Payload CMS to version 3.90.0 or higher (for 3.x installations) or 4.0.0-canary.34 or higher (for 4.x installations).
- Explicitly set disableDuplicate: true in all authentication-enabled and high-privilege collection configurations.
- Implement custom beforeChange or beforeValidate hooks to strip sensitive fields during duplication operations programmatically.
Remediation Steps:
- Analyze the active Payload CMS version in package.json.
- Run npm install [email protected] or npm install [email protected] depending on the track.
- Audit all collection configurations and append disableDuplicate: true to users and administrative schemas.
- Rebuild the application and deploy the patch to staging and production systems.
- Verify that POST requests to /api/users/:id/duplicate return a 400 or 404 response status.
References
- GitHub Security Advisory GHSA-vc4h-q48j-5hcx
- Payload CMS Commit 099ef12e26
- Payload CMS v3.90.0 Release Notes
- CVE-2026-105851 Record
Read the full report for CVE-2026-105851 on our website for more details including interactive diagrams and full exploit analysis.
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.