← Back to CVE List
CVE-2026-105851NVD
Vulnerability Summary
Payload is a free and open source headless content management system. In versions from 3.0.0 before 3.90.0 and canary versions before 4.0.0-canary.34, the duplicate operation copies values from a source document even when a field is hidden or its access.read or access.create rule rejects that value for the caller. The disableDuplicate setting does not prevent this access-control bypass. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
CVSS v4.0 Base Metrics — Score 9.3 (CRITICAL)
Attack VectorNetwork
Attack ComplexityLow
Attack RequirementsNone
Privileges RequiredNone
User InteractionNone
Confidentiality (Vulnerable System)None
Integrity (Vulnerable System)High
Availability (Vulnerable System)None
Confidentiality (Subsequent System)High
Integrity (Subsequent System)High
Availability (Subsequent System)None
Affected & Patched Versions
- payloadcms payload >= > 3.0.0, < 3.90.0
- payloadcms payload >= > 4.0.0-canary.0, < 4.0.0-canary.34
Not provided by cveorg for this CVE.