CRITICAL🇵🇱 Wersja polska

CVE-2026-34751

CVSS 9.1v3.1pub. 2026-04-01upd. 2026-04-15

Payload is a free and open source headless content management system. Prior to version 3.79.1 in @payloadcms/graphql and payload, a vulnerability in the password recovery flow could allow an unauthenticated attacker to perform actions on behalf of a user who initiates a password reset. This issue has been patched in version 3.79.1 for @payloadcms/graphql and payload.

🤖 AI Analysis
How it works

The vulnerability affects the password recovery flow (CWE-640) and improper authentication parameter management (CWE-472). An attacker without any privileges can abuse the password reset process initiated by a victim and take control of their session or perform actions on their behalf. The vulnerability does not require interaction from the attacker beyond the reset flow — it is sufficient that a legitimate user initiates the password recovery procedure.

Impact

An attacker can gain unauthorized access to a user account and modify data or content managed by Payload CMS on behalf of the victim, leading to a breach of data confidentiality and integrity.

Mitigation & patch

Update the @payloadcms/graphql and payload packages to version 3.79.1 or newer, where the vulnerability has been removed. Details are available in the vendor references on GitHub.

Who is affected

The @payloadcms/graphql and payload packages in all versions prior to 3.79.1

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  • Payloadcms Payload

    APP
    Payloadcms
    < 3.79.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2026-25544CRITICAL9.8PL ✓same product

SQL Injection w Payload CMS — przejęcie konta bez uwierzytelnienia

CVE-2022-27952CRITICAL9.8PL ✓same product

PayloadCMS: RCE poprzez nieograniczony upload pliku SVG

CVE-2026-34746HIGH7.7same product

Payload is a free and open source headless content management system. Prior to version 3.79.1, an authenticate...

CVE-2026-34747HIGH8.5same product

Payload is a free and open source headless content management system. Prior to version 3.79.1, certain request...

CVE-2026-34748HIGH8.7same product

Payload is a free and open source headless content management system. Prior to version 3.78.0 in @payloadcms/n...