Description
Payload is a free and open source headless content management system. In versions from 3.0.0 before 3.90.0 and canary versions before 4.0.0-canary.34, a user who can query a collection with a polymorphic join to sensitive fields can infer hidden or read-restricted values, including password-reset tokens, through polymorphic join filters. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
Published: 2026-10-06
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Sensitive Data Disclosure
Action: Patch
AI Analysis

Impact

A vulnerability in Payload CMS allows an attacker who can query a collection using a polymorphic join to infer hidden or read‑restricted values. The flaw can expose sensitive fields such as password‑reset tokens by leveraging join filters. This results in a confidentiality breach and aligns with CWE‑200 (Information Exposure) and CWE‑639 (Privilege Escalation through Inadequate Access Control).

Affected Systems

The affected product is Payload CMS versions from 3.0.0 up to but not including 3.90.0, as well as canary releases before 4.0.0‑canary.34. All customers running these versions are vulnerable unless they have applied the fix in the announced releases.

Risk and Exploitability

The CVSS score of 7.1 classifies the issue as high severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw by sending specially crafted collection queries that employ polymorphic joins to sensitive fields; the attack vector is likely remote through the web APIs if access control is not properly enforced.

Generated by OpenCVE AI on October 6, 2026 at 18:03 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Payload CMS to version 3.90.0 or later, or to release 4.0.0‑canary.34 or a newer canary.
  • Restrict or disable polymorphic join functionality for collections containing sensitive fields until the patch is applied.
  • Ensure that only authorized user roles have permission to execute collection queries that involve polymorphic joins to protected data.
  • Review and tighten overall access controls to reduce the ability of unauthenticated or low‑privilege users to perform join operations on sensitive collections.

Generated by OpenCVE AI on October 6, 2026 at 18:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-fpww-c55p-cjv6 Payload: Polymorphic join queries could disclose hidden fields
History

Tue, 06 Oct 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Description Payload is a free and open source headless content management system. In versions from 3.0.0 before 3.90.0 and canary versions before 4.0.0-canary.34, a user who can query a collection with a polymorphic join to sensitive fields can infer hidden or read-restricted values, including password-reset tokens, through polymorphic join filters. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
Title Payload: Polymorphic join queries could disclose hidden fields
Weaknesses CWE-200
CWE-639
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-06T17:22:16.944Z

Reserved: 2026-10-05T23:06:29.747Z

Link: CVE-2026-105847

cve-icon Vulnrichment

Updated: 2026-10-06T17:22:13.774Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-06T17:17:20.143

Modified: 2026-10-06T20:03:40.690

Link: CVE-2026-105847

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T18:15:04Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-639

    Authorization Bypass Through User-Controlled Key