Description
Payload Plugins is a collection of plugins designed to enhance Payload CMS. In 0.7.0, @jhb.software/payload-alt-text-plugin exposes POST /api/alt-text-plugin/generate and POST /api/alt-text-plugin/bulk with a default guard that accepts any authenticated user, while alt-text/src/endpoints/generateAltText.ts and alt-text/src/endpoints/bulkGenerateAltTexts.ts call req.payload.findByID and req.payload.update without overrideAccess: false. Payload therefore defaults overrideAccess to true and skips the target collection's read and update access functions. An authenticated low-privilege user can supply id, collection, locale, and update values to read arbitrary protected upload documents and overwrite their alt and keywords fields, even when the collection permits those operations only to administrators. A control Local API call with overrideAccess: false is denied, confirming that the plugin endpoint bypasses otherwise effective collection rules. This vulnerability is fixed in 0.8.0.
Published: 2026-09-15
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized read and modification of protected documents
Action: Patch
AI Analysis

Impact

Payload Plugins version 0.7.0 contains a plugin called payload‑alt‑text‑plugin that exposes two POST endpoints: /api/alt‑text‑plugin/generate and /api/alt‑text‑plugin/bulk. These endpoints are protected by a generic guard that accepts any authenticated user, and the handlers call req.payload.findByID and req.payload.update without setting overrideAccess to false. Because overrideAccess defaults to true, the handlers bypass the target collection’s read and update access checks, allowing an authenticated low‑privilege user to supply an id, collection name, locale, and new values in the request body to read and modify any protected upload document’s alt and keywords fields, even when the collection is configured to permit those operations only for administrators. A local API call that sets overrideAccess to false is correctly denied, confirming that the plugin endpoint is the source of the bypass. The vulnerability is addressed in alt‑text‑plugin version 0.8.0.

Affected Systems

The vulnerability affects the JHB Software Payload Plugins, specifically the payload‑alt‑text‑plugin submodule. The issue is present in version 0.7.0 of the plugin and is fixed in version 0.8.0. No other affected versions are reported in the input.

Risk and Exploitability

The CVSS score of 7.1 indicates medium to high severity, and the EPSS score is < 1 %, indicating a very low but non‑zero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed widespread exploitation. However, because the flaw can be leveraged by any authenticated user and the bypass requires only normal POST calls to the plugin endpoints, the likelihood of exploitation is non‑negligible in environments where the plugin is enabled and lower‑privilege users exist. Once exploited, the attacker can read and tamper with protected documents, potentially compromising the confidentiality and integrity of content.

Generated by OpenCVE AI on September 20, 2026 at 16:11 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to version 0.8.0 or later
  • Disable or uninstall the alt‑text plugin if an upgrade is not feasible
  • Restrict non‑administrator users from accessing the alt‑text plugin endpoints and ensure that document update permissions are set to administrator only

Generated by OpenCVE AI on September 20, 2026 at 16:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-4qpv-39hg-f7fx @jhb.software/payload-alt-text-plugin: Alt Text Endpoint Authorization Bypass via Payload Local API `overrideAccess` Omission
History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Jhb-software
Jhb-software payload-alt-text-plugin
Jhb-software payload-plugins
Vendors & Products Jhb-software
Jhb-software payload-alt-text-plugin
Jhb-software payload-plugins

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description Payload Plugins is a collection of plugins designed to enhance Payload CMS. In 0.7.0, @jhb.software/payload-alt-text-plugin exposes POST /api/alt-text-plugin/generate and POST /api/alt-text-plugin/bulk with a default guard that accepts any authenticated user, while alt-text/src/endpoints/generateAltText.ts and alt-text/src/endpoints/bulkGenerateAltTexts.ts call req.payload.findByID and req.payload.update without overrideAccess: false. Payload therefore defaults overrideAccess to true and skips the target collection's read and update access functions. An authenticated low-privilege user can supply id, collection, locale, and update values to read arbitrary protected upload documents and overwrite their alt and keywords fields, even when the collection permits those operations only to administrators. A control Local API call with overrideAccess: false is denied, confirming that the plugin endpoint bypasses otherwise effective collection rules. This vulnerability is fixed in 0.8.0.
Title @jhb.software/payload-alt-text-plugin: Alt Text Endpoint Authorization Bypass via Payload Local API `overrideAccess` Omission
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N'}


Subscriptions

Jhb-software Payload-alt-text-plugin Payload-plugins
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-17T15:32:58.542Z

Reserved: 2026-07-07T18:49:15.608Z

Link: CVE-2026-59965

cve-icon Vulnrichment

Updated: 2026-09-17T15:32:52.749Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T16:17:17.110

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-59965

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T16:15:18Z

Weaknesses