Back

MEDIUM

User Session Fixation after Account Removal in PayloadCMS

Published Aug 29, 2025

Description

A Session Fixation vulnerability existed in Payload's SQLite adapter due to identifier reuse during account creation. A malicious attacker could create a new account, save its JSON Web Token (JWT), and then delete the account, which did not invalidate the JWT. As a result, the next newly created user would receive the same identifier, allowing the attacker to reuse the JWT to authenticate and perform actions as that user.

This issue has been fixed in version 3.44.0 of Payload.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner CERT-PL
Published Aug 29, 2025
Updated Aug 29, 2025
Reserved May 13, 2025
CISA Vulnrichment
Updated Aug 29, 2025
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner CERT-PL
Published Aug 29, 2025
Updated Aug 29, 2025
Exploited since n/a
EUVD-2025-26181 GHSA-26RV-H2HF-3FW4