Description
Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, the server fails to enforce a field-level access.update restriction on the password field of an authentication collection. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
Published: 2026-10-06
Score: 7.6 High
EPSS: n/a
KEV: No
Impact: Unauthorized modification of authentication credentials
Action: Patch
AI Analysis

Impact

The server fails to enforce a field‑level access.update restriction on the password field of the authentication collection, allowing any user who can send an update request to change another user’s password. This flaw enables unauthorized modification of authentication credentials and can lead to account takeover.

Affected Systems

Payload CMS (payloadcms:payload) is affected in all releases before version 3.90.0 and in canary builds before 4.0.0-canary.34. Users running these versions are at risk until the fix is applied by upgrading to the latest patch release.

Risk and Exploitability

The vulnerability is classified as Improper Access Control with a CVSS score of 7.6, indicating a high severity. An attacker only needs the ability to submit an update payload targeting the password field; no additional system access or privilege escalation is required. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog, but the high CVSS score still signifies a significant risk if left unresolved.

Generated by OpenCVE AI on October 6, 2026 at 18:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Payload CMS to version 3.90.0 or later, or to 4.0.0-canary.34 or newer to apply the fix
  • After upgrade, confirm that the password field in the authentication collection has a field‑level update restriction enabled in its configuration
  • Limit update permissions for the password field to privileged roles only, revoking any lower‑privileged user rights that may exist

Generated by OpenCVE AI on October 6, 2026 at 18:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-fx49-4h83-wjv9 Payload didn't enforce field-level password update restrictions
History

Tue, 06 Oct 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 16:45:00 +0000

Type Values Removed Values Added
Description Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, the server fails to enforce a field-level access.update restriction on the password field of an authentication collection. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
Title Payload: Field-level password update restrictions were not enforced
Weaknesses CWE-284
References
Metrics cvssV4_0

{'score': 7.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-06T17:18:56.091Z

Reserved: 2026-10-05T23:06:29.748Z

Link: CVE-2026-105855

cve-icon Vulnrichment

Updated: 2026-10-06T17:18:48.119Z

cve-icon NVD

Status : Received

Published: 2026-10-06T17:17:21.430

Modified: 2026-10-06T18:16:48.847

Link: CVE-2026-105855

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T18:30:05Z

Weaknesses