Dev.to Security 🔐 Cybersecurity 👁 0 📖 1 min read

CVE-2026-105855: CVE-2026-105855: Privilege Escalation via Improper Access Control on Password Fields in Payload CMS

CVE-2026-105855: Privilege Escalation via Improper Access Control on Password Fields in Payload CMS Vulnerability ID: CVE-2026-105855 CVSS Score: 7.6 Published: 2026-10-06 An Improper Access Control vulnerability (C

CVE-2026-105855: Privilege Escalation via Improper Access Control on Password Fields in Payload CMS

Vulnerability ID: CVE-2026-105855
CVSS Score: 7.6
Published: 2026-10-06

An Improper Access Control vulnerability (CWE-284) in Payload CMS prior to version 3.90.0 and 4.0.0-canary.34 allows authenticated, low-privileged users to bypass field-level access control restrictions and overwrite the password of other accounts, leading to complete account takeover and privilege escalation.

TL;DR

An authentication bypass and privilege escalation vulnerability in Payload CMS allows authenticated users to overwrite the passwords of other accounts, including administrators, due to premature password extraction prior to access control validation.

⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-284
  • Attack Vector: Network (AV:N)
  • CVSS v4.0 Score: 7.6 (High)
  • EPSS Score: Not Available
  • Exploit Status: poc
  • KEV Status: Not Listed

Affected Systems

  • Payload CMS
  • payload: < 3.90.0 (Fixed in: 3.90.0)
  • payload: >= 4.0.0-canary.0 < 4.0.0-canary.34 (Fixed in: 4.0.0-canary.34)

Code Analysis

Commit: 9de9e79

Fix field access.update bypass on password fields

Mitigation Strategies

  • Upgrade Payload CMS to a patched version (v3.90.0+ or v4.0.0-canary.34+)
  • Monitor API traffic for unauthorized PATCH/PUT requests targeting authentication endpoints
  • Audit collection access control configurations

Remediation Steps:

  1. Open the project package.json file.
  2. Update the 'payload' dependency to '3.90.0' or newer (or '4.0.0-canary.34' or newer for canary users).
  3. Run the package manager install command (e.g., npm install, yarn install, or pnpm install).
  4. Verify the installed version in package-lock.json or yarn.lock.
  5. Deploy the updated application to production environments.

References

Read the full report for CVE-2026-105855 on our website for more details including interactive diagrams and full exploit analysis.

📰 Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.