Impact
A vulnerability in Payload CMS allows an attacker who can query a collection using a polymorphic join to infer hidden or read‑restricted values. The flaw can expose sensitive fields such as password‑reset tokens by leveraging join filters. This results in a confidentiality breach and aligns with CWE‑200 (Information Exposure) and CWE‑639 (Privilege Escalation through Inadequate Access Control).
Affected Systems
The affected product is Payload CMS versions from 3.0.0 up to but not including 3.90.0, as well as canary releases before 4.0.0‑canary.34. All customers running these versions are vulnerable unless they have applied the fix in the announced releases.
Risk and Exploitability
The CVSS score of 7.1 classifies the issue as high severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw by sending specially crafted collection queries that employ polymorphic joins to sensitive fields; the attack vector is likely remote through the web APIs if access control is not properly enforced.
OpenCVE Enrichment
Github GHSA