Back

HIGH

Payload: Token refresh and password reset responses may expose restricted user fields

Published Oct 6, 2026

Description

Payload is a free and open source headless content management system. In versions from 3.0.0 before 3.90.0 and canary versions before 4.0.0-canary.34, token refresh responses and password reset responses can independently return hidden or read-restricted fields that the requesting user cannot access. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.

Affected products

Remediation

No remediation recorded yet.

References (5)

Change history (2)
  1. EUVD
    • Updated

      changed from Oct 6, 2026 to Oct 6, 2026

    • Published

      changed from Oct 6, 2026 to Oct 6, 2026

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner GitHub_M
Published Oct 6, 2026
Updated Oct 6, 2026
Reserved Oct 5, 2026

CISA Vulnrichment

No data

NVD

Status Awaiting Analysis
Modified Oct 6, 2026

Red Hat

No data

ENISA EUVD

Assigner GitHub_M
Published Oct 6, 2026
Updated Oct 6, 2026