Dev.to Security 🔐 Cybersecurity 👁 0 📖 1 min read

CVE-2026-105851: CVE-2026-105851: Privilege Escalation via Field Access Control Bypass in Payload CMS Duplication Mechanism

CVE-2026-105851: Privilege Escalation via Field Access Control Bypass in Payload CMS Duplication Mechanism Vulnerability ID: CVE-2026-105851 CVSS Score: 9.3 Published: 2026-10-06 A critical access control bypass vul

CVE-2026-105851: Privilege Escalation via Field Access Control Bypass in Payload CMS Duplication Mechanism

Vulnerability ID: CVE-2026-105851
CVSS Score: 9.3
Published: 2026-10-06

A critical access control bypass vulnerability (CVE-2026-105851) in Payload CMS allows authenticated users to bypass field-level access controls during document duplication. By duplicating high-privilege documents, such as administrator accounts, standard users can inherit sensitive fields (e.g., role configurations or API keys), leading to privilege escalation.

TL;DR

Payload CMS failed to enforce field-level access controls and the disableDuplicate configuration during document duplication, allowing standard users to duplicate administrator profiles and escalate their privileges.

⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-284 / CWE-863
  • Attack Vector: Network (Unauthenticated or Low-Privileged Local Network/API Access)
  • CVSS v4.0: 9.3 (Critical)
  • EPSS Score: Not Available
  • Impact: Privilege Escalation / Unauthorized Data Access
  • Exploit Status: Conceptual / Proof-of-Concept
  • CISA KEV Status: Not Listed

Affected Systems

  • Payload CMS
  • payload: >= 3.0.0, < 3.90.0 (Fixed in: 3.90.0)
  • payload: >= 4.0.0-canary.0, < 4.0.0-canary.34 (Fixed in: 4.0.0-canary.34)

Code Analysis

Commit: 099ef12

Field access control bypass on auth collections fix

Mitigation Strategies

  • Upgrade Payload CMS to version 3.90.0 or higher (for 3.x installations) or 4.0.0-canary.34 or higher (for 4.x installations).
  • Explicitly set disableDuplicate: true in all authentication-enabled and high-privilege collection configurations.
  • Implement custom beforeChange or beforeValidate hooks to strip sensitive fields during duplication operations programmatically.

Remediation Steps:

  1. Analyze the active Payload CMS version in package.json.
  2. Run npm install [email protected] or npm install [email protected] depending on the track.
  3. Audit all collection configurations and append disableDuplicate: true to users and administrative schemas.
  4. Rebuild the application and deploy the patch to staging and production systems.
  5. Verify that POST requests to /api/users/:id/duplicate return a 400 or 404 response status.

References

Read the full report for CVE-2026-105851 on our website for more details including interactive diagrams and full exploit analysis.

📰 Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.