@delmaredigital/payload-puc is missing authorization on /api/puck/* CRUD endpoints allows unauthenticated access to Puck-registered collections
Published Apr 7, 2026
9.8
CRITICALCVSS 3.1
EPSS 0.61%
Description
@delmaredigital/payload-puck is a PayloadCMS plugin for integrating Puck visual page builder. Prior to 0.6.23, all /api/puck/* CRUD endpoint handlers registered by createPuckPlugin() called Payload's local API with the default overrideAccess: true, bypassing all collection-level access control. The access option passed to createPuckPlugin() and any access rules defined on Puck-registered collections were silently ignored on these endpoints. This vulnerability is fixed in 0.6.23.
Affected products
-
Affected
- < 0.6.23
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Delmaredigital | Payload-Puck | unknown | Affected
|
- < 0.6.23
No data.
No Red Hat product state for this CVE.
@delmaredigital/payload-puck
npm
Introduced 0 Fixed 0.6.23
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | @delmaredigital/payload-puck | 0 | 0.6.23 |
Remediation
No remediation recorded yet.
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-19921 Advisory
- https://github.com/advisories/GHSA-65w6-pf7x-5g85 Advisory
- https://github.com/delmaredigital/payload-puck/commit/9148201c6bbfa140d44546438027a2f8a70f79a4 x_refsource_MISCPatch
- https://github.com/delmaredigital/payload-puck/issues/7 x_refsource_MISCExploitIssue Tracking
- https://github.com/delmaredigital/payload-puck/security/advisories/GHSA-65w6-pf7x-5g85 x_refsource_CONFIRMPatchVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-39397
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-19921 | Advisory | |
| https://github.com/advisories/GHSA-65w6-pf7x-5g85 | Advisory | |
| https://github.com/delmaredigital/payload-puck/commit/9148201c6bbfa140d44546438027a2f8a70f79a4 | x_refsource_MISCPatch | |
| https://github.com/delmaredigital/payload-puck/issues/7 | x_refsource_MISCExploitIssue Tracking | |
| https://github.com/delmaredigital/payload-puck/security/advisories/GHSA-65w6-pf7x-5g85 | x_refsource_CONFIRMPatchVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-39397 |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub