Description
Payload is a free and open source headless content management system. In versions from 3.0.0 before 3.90.0 and canary versions before 4.0.0-canary.34, token refresh responses and password reset responses can independently return hidden or read-restricted fields that the requesting user cannot access. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
Published: 2026-10-06
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Sensitive Data Exposure
Action: Apply patch
AI Analysis

Impact

Token refresh and password reset responses in PayloadCMS may return hidden or read‑restricted user fields that the requesting user cannot normally see, exposing sensitive data to unauthorized actors. This is an information disclosure vulnerability as defined by CWE‑200, which can compromise user confidentiality and potentially reveal data that should be protected by role‑based access controls.

Affected Systems

PayloadCMS systems running the Payload component are affected. All releases from version 3.0.0 up through the last release prior to 3.90.0, as well as canary releases before 4.0.0‑canary.34, contain the issue. Versions 3.90.0 and 4.0.0‑canary.34 or later have the fix and are not vulnerable.

Risk and Exploitability

The vulnerability scores a CVSS of 7.1, reflecting a medium to high severity. The issue is not listed in the CISA KEV catalog, so the exploitation likelihood is uncertain. The likely attack vector is remote over the network via the standard web API; an attacker who can invoke a token‑refresh or password‑reset operation can retrieve unauthorized user information, potentially facilitating further credential or privilege escalation.

Generated by OpenCVE AI on October 6, 2026 at 18:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to PayloadCMS version 3.90.0 or later, or to 4.0.0‑canary.34 or later.
  • If an immediate upgrade cannot be performed, restrict or temporarily block access to the token‑refresh and password‑reset endpoints until the vulnerability is patched.
  • Implement a middleware or configuration change that removes any hidden or read‑restricted fields from token‑refresh and password‑reset responses for users lacking the appropriate permissions.

Generated by OpenCVE AI on October 6, 2026 at 18:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-xgv3-crq2-6f69 Payload: Token refresh and password reset responses may expose restricted user fields
History

Tue, 06 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Description Payload is a free and open source headless content management system. In versions from 3.0.0 before 3.90.0 and canary versions before 4.0.0-canary.34, token refresh responses and password reset responses can independently return hidden or read-restricted fields that the requesting user cannot access. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
Title Payload: Token refresh and password reset responses may expose restricted user fields
Weaknesses CWE-200
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-06T16:16:14.512Z

Reserved: 2026-10-05T23:06:29.748Z

Link: CVE-2026-105853

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-06T17:17:21.140

Modified: 2026-10-06T17:17:21.140

Link: CVE-2026-105853

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T18:45:05Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor