CVE-2026-105853: CVE-2026-105853: Sensitive Information Disclosure and Authentication Collection Boundary Bypass in Payload CMS
CVE-2026-105853: Sensitive Information Disclosure and Authentication Collection Boundary Bypass in Payload CMS Vulnerability ID: CVE-2026-105853 CVSS Score: 7.1 Published: 2026-10-06 CVE-2026-105853 is a high-severi
CVE-2026-105853: Sensitive Information Disclosure and Authentication Collection Boundary Bypass in Payload CMS
Vulnerability ID: CVE-2026-105853
CVSS Score: 7.1
Published: 2026-10-06
CVE-2026-105853 is a high-severity information disclosure vulnerability in Payload CMS that affects authentication-enabled collections. In vulnerable versions, the application fails to properly serialize and sanitize user documents during token refresh and password reset operations. This deficiency leaks hidden and read-restricted fields to unauthorized actors. Additionally, a logical flaw in token refresh validation allows low-privileged users to cross collection boundaries, exposing sensitive configuration details and administrative metadata.
TL;DR
Payload CMS fails to sanitize user documents in password reset and token refresh endpoints, allowing low-privileged authenticated users to access hidden or read-restricted fields across collection boundaries.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-200
- Attack Vector: Network (AV:N)
- CVSS v4.0 Score: 7.1
- EPSS Score: Not yet populated
- Impact: High Confidentiality Exposure
- Exploit Status: poc
- KEV Status: No
Affected Systems
- Payload CMS installations with multiple authentication-enabled collections
- Payload CMS installations with custom fields marked as hidden
-
payload: >= 3.0.0, < 3.90.0 (Fixed in:
3.90.0) -
payload: >= 4.0.0-canary.0, < 4.0.0-canary.34 (Fixed in:
4.0.0-canary.34)
Code Analysis
Commit: f5f1283
Fix token refresh collection boundary verification check
Mitigation Strategies
- Upgrade Payload CMS dependencies to versions that contain the official security patches.
- Manually review and sanitize user documents returned by custom authentication handlers.
- Deploy WAF rules to monitor and block cross-collection token refresh requests.
Remediation Steps:
- Identify the current version of Payload CMS running in the package.json file.
- Upgrade the package to version 3.90.0 or higher for 3.x branches, or version 4.0.0-canary.34 or higher for 4.x branches.
- Rebuild and redeploy the application.
- Inspect custom authentication strategies and ensure they apply appropriate sanitization wrappers.
References
- GitHub Security Advisory GHSA-xgv3-crq2-6f69
- Fix Commit (Token Refresh Collection Boundary)
- Payload CMS Release Version 3.90.0
Read the full report for CVE-2026-105853 on our website for more details including interactive diagrams and full exploit analysis.
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.