Payload: Token refresh and password reset responses may expose restricted user fields
Published Oct 6, 2026
7.1
HIGHCVSS 4.0
EPSS 0.26%
Description
Payload is a free and open source headless content management system. In versions from 3.0.0 before 3.90.0 and canary versions before 4.0.0-canary.34, token refresh responses and password reset responses can independently return hidden or read-restricted fields that the requesting user cannot access. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
Affected products
-
Affected
- ≥ 3.0.0, < 3.90.0
- ≥ 4.0.0-canary.0, < 4.0.0-canary.34
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Payloadcms | Payload | unknown | Affected
|
No data.
No data.
No Red Hat product state for this CVE.
payload
npm
Introduced 3.0.0 Fixed 3.90.0payload
npm
Introduced 4.0.0-canary.0 Fixed 4.0.0-canary.34
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | payload | 3.0.0 | 3.90.0 |
| npm | payload | 4.0.0-canary.0 | 4.0.0-canary.34 |
Remediation
No remediation recorded yet.
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-93497 Advisory
- https://github.com/advisories/GHSA-xgv3-crq2-6f69 Advisory
- https://github.com/payloadcms/payload/commit/f5f1283d275c58b30e2faa6be7cdc4d49451ea91 x_refsource_MISC
- https://github.com/payloadcms/payload/releases/tag/v3.90.0 x_refsource_MISC
- https://github.com/payloadcms/payload/security/advisories/GHSA-xgv3-crq2-6f69 x_refsource_CONFIRM
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-93497 | Advisory | |
| https://github.com/advisories/GHSA-xgv3-crq2-6f69 | Advisory | |
| https://github.com/payloadcms/payload/commit/f5f1283d275c58b30e2faa6be7cdc4d49451ea91 | x_refsource_MISC | |
| https://github.com/payloadcms/payload/releases/tag/v3.90.0 | x_refsource_MISC | |
| https://github.com/payloadcms/payload/security/advisories/GHSA-xgv3-crq2-6f69 | x_refsource_CONFIRM |
Change history (2)
- EUVD
Updated
changed from Oct 6, 2026 to Oct 6, 2026Oct 6, 2026 → Oct 6, 2026
Published
changed from Oct 6, 2026 to Oct 6, 2026Oct 6, 2026 → Oct 6, 2026
CVE.org / MITRE
CISA Vulnrichment
No data
Red Hat
No data
GitHub