External risk intelligence

Payload CMS Duplicate Operation Access Control Bypass

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-105851

Payload is a content management system designed to serve web content and manage APIs. As a web-based CMS, it is commonly deployed as an internet-facing application to support public-facing websites, services, and administrative interfaces.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory addresses a vulnerability in the Payload content management system that allows unauthorized access to data during a duplication operation. The issue stems from the system copying data even when access controls should prevent it, bypassing a specific setting designed to disable this function. While Payload is designed for managing content, the impact of this vulnerability depends on how it is configured and utilized within an organization.

  • Data copied without proper access controls.
  • Affects systems that duplicate content.
  • Confirm relevance and exposure of your configurations.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by leveraging the duplicate operation within the content management system. This operation mishandles field access rules, allowing the attacker to copy data from a source document regardless of whether the target field is hidden or if the attacker lacks the necessary permissions to create or read it. This bypass of access controls can lead to unauthorized data exposure and modification.

  • No specific entry conditions needed.
  • Triggered by the duplicate document operation.
  • Risk of unauthorized data access and changes.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow unauthorized data copying during the duplicate operation in Payload, bypassing field-level access controls. This may affect system data and sensitive information when the duplicate function is utilized.

  • Sensitive system data could be exposed.
  • Data is copied despite access restrictions.
  • Unauthorized access to duplicate content.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Platform or Infrastructure team is likely responsible for managing and remediating this vulnerability in Payload, given its role as a headless CMS. The initial step should be to inventory all deployed Payload instances, confirm their reachability and business criticality, and identify the specific application owners for each. This will allow for prioritized remediation planning.

  • Platform/Infrastructure owns the issue.
  • Verify all Payload instances and reachability.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Payload CMS?

Payload is a free, open-source headless content management system. Unlike traditional platforms, it manages content via APIs, allowing developers to build flexible backends for websites and applications. It is frequently deployed to handle data structures and administrative interfaces for modern web services.

How does CVE-2026-105851 bypass security?

This vulnerability falls under Improper Access Control. In affected versions, the system's document duplication feature fails to respect field-level permissions. It copies restricted or hidden data from a source document into a new one, effectively ignoring read or create access rules and the disableDuplicate configuration.

Do I need to take a specific action to trigger this bug?

No complex preconditions are required. The flaw is triggered simply by performing a duplicate operation on a document. It is important to note that the vulnerability is not tied to a specific type of user or authentication state; the logic error exists within the core copy process regardless of most standard access configurations.

Why should I care about this vulnerability?

According to Halo Surface Signal, Payload is commonly deployed as an internet-facing application. Because this bug allows unauthorized data access, any instance exposed to the network or accessible by untrusted users carries a heightened risk of sensitive information being copied or improperly modified during document duplication.

When should I update my Payload instance?

You should prioritize updating as soon as you have inventoried your instances. Start by identifying all running versions to see if they fall within the affected ranges. Once you have a clear list of deployments and their owners, apply the fix by upgrading to version 3.90.0 or 4.0.0-canary.34 to resolve the access control flaw.

References