CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



CVE-2026-34751

CVE-2026-34751: Unvalidated Input in Password Recovery Endpoints in Payload CMS

Amit Schendel
Amit Schendel
Senior Security Researcher

Apr 1, 2026·7 min read·113 visits

Executive Summary (TL;DR)

A critical flaw in Payload CMS (< 3.79.1) permits unauthenticated attackers to achieve account takeover through Host header injection in password reset emails and database query partial-match misconfigurations.

Payload CMS prior to version 3.79.1 contains a critical vulnerability in its password recovery endpoints. This flaw allows an unauthenticated attacker to manipulate password reset links via Host header injection and exploit partial token matches in database adapters, leading to unauthorized account takeover.

Vulnerability Overview

Payload CMS is an open-source headless content management system built on Node.js. Versions prior to 3.79.1 exhibit a critical vulnerability within the password recovery workflow. The flaw specifically resides in the /api/{collection-slug}/forgot-password endpoint, which is exposed to unauthenticated network requests by design to facilitate account recovery.

The vulnerability is primarily classified under CWE-640 (Weak Password Recovery Mechanism for Forgotten Password). The application fails to strictly validate request metadata, specifically the HTTP Host header, before utilizing it to construct absolute URLs for password reset emails. This oversight allows external actors to control the destination domain of generated recovery links.

Furthermore, the vulnerability is compounded by logic flaws within the database adapters for MongoDB and Drizzle. Query operators designed for fields with the hasMany property improperly handle partial matching, allowing token search entropy reduction. This combination of input validation failures and query logic flaws facilitates unauthenticated account takeover.

Root Cause Analysis

The primary root cause is the reliance on user-controlled input for security-sensitive URL generation. When a user requests a password reset, the application requires an absolute URL to embed in the outbound recovery email. The vulnerable implementation derives the scheme and domain from the HTTP Host header or a user-supplied url parameter instead of relying strictly on a statically defined configuration value.

A secondary root cause exists in the query construction logic within the database adapters. The contains operator, when applied to fields possessing the hasMany attribute, utilizes partial matching mechanisms such as SQL LIKE %value% or regular expressions. This behavior becomes a critical security boundary failure when applied to high-entropy authentication tokens.

An attacker queries the database using a single character for the contains operation during a token lookup. The database engine returns the first record where the token contains that specific character. This drastically reduces the search space for the token from a secure 64-character string down to a highly probable single-character match, effectively bypassing the cryptographic token validation logic.

A tertiary issue involves polymorphic join scoping within the Drizzle SQL adapter. The adapter applies LIMIT and OFFSET clauses globally across the entire result set rather than scoping them per parent record. An attacker floods the system with reset requests, exhausting the global limit and causing legitimate user token queries to return empty result sets.

Code Analysis

In the vulnerable implementation of the URL generation logic, the framework extracts the host directly from the incoming request headers. This design pattern violates the principle of strictly trusting server-side configuration for critical application paths. The framework effectively trusts the client-provided environment variables to build the base structure of the reset link.

The patched version enforces the usage of a strictly defined serverURL variable within the Payload configuration. All auth-related email link constructions now reference this trusted configuration property, completely ignoring the client-provided Host header or custom query parameters. This architectural change severs the attacker's ability to inject arbitrary domains.

Regarding the query operator flaw, commit fba24380578f513209a5f4811e2836a2317c33d2 addresses the partial matching mechanism. The fix modifies the contains logic applied to hasMany fields. The updated code enforces strict equality checks for sensitive identifiers rather than falling back to LIKE or Regex partial matches, preventing the entropy reduction attack.

Commit fe36dded4bcf1c54289c6687bb2308d02fbeba99 corrects the polymorphic join limits. The query builder accurately isolates LIMIT constraints to individual parent records during nested relationship resolution. This ensures that an arbitrary number of unrelated records cannot exhaust the limit boundary for legitimate users.

Exploitation Methodology

Exploiting the Host header injection requires the attacker to send a single, unauthenticated POST request to the forgot-password endpoint. The attacker sets the Host header to an attacker-controlled server and provides the target victim's email address in the request body. The application generates a valid cryptographic reset token and embeds it into a URL pointing to the malicious host.

The system dispatches the recovery email to the victim. Because the email originates from the legitimate service provider, it easily bypasses SPF and DKIM checks and presents a high degree of apparent authenticity to the victim. When the victim clicks the link, their client initiates a request to the attacker-controlled server.

The attacker intercepts the HTTP request and extracts the reset token from the URL path or query parameters. The attacker then submits this valid token to the legitimate application's password reset endpoint, establishes a new password, and achieves complete account takeover.

Alternatively, an attacker exploits the contains query misconfiguration by crafting a custom JSON payload for the password reset endpoint. By supplying {"where": {"resetPasswordToken": {"contains": "a"}}}, the attacker forces the database to evaluate a partial match. The system authenticates the request against the first matching user record, granting unauthorized access without requiring victim interaction.

Impact Assessment

The successful exploitation of this vulnerability results in unauthenticated, remote account takeover. An attacker compromises any user account, including administrative accounts, provided they know the target user's email address. This leads to a complete breach of confidentiality and integrity for the affected accounts and the underlying CMS platform.

With administrative access, the attacker manipulates content, alters system configurations, exfiltrates sensitive database records, and potentially achieves remote code execution depending on the specific Payload CMS configuration and active plugins. The impact scales directly with the privileges of the compromised account.

The vulnerability carries a CVSS v3.1 base score of 9.1 (Critical). The exploit requires no specialized network positioning, demands no prior authentication, and involves minimal attack complexity. While the Host header injection vector requires user interaction (the victim clicking the link), the query operator bypass functions entirely autonomously.

Furthermore, the polymorphic join limit exhaustion introduces a localized Denial of Service (DoS) condition. An attacker iteratively submits reset requests, polluting the database and preventing legitimate users from completing their password recovery workflows. This disrupts the availability of the authentication service.

Remediation and Mitigation

The primary and most effective remediation is immediately upgrading the Payload CMS installation to version 3.79.1. This release patches all identified attack vectors, including the Host header injection, the query operator partial matching, and the polymorphic join limit scoping. Administrators must update both the payload and @payloadcms/graphql packages in their dependency trees.

Administrators must explicitly configure the serverURL property within the main Payload configuration object. This dictates the absolute origin used for all system-generated URLs, ensuring the framework strictly utilizes a known environment variable rather than evaluating client-provided HTTP headers during email link construction.

> [!NOTE] > Relying on default configurations in earlier versions exposes the application. Verifying serverURL is correctly populated is a mandatory post-patching step.

As a defense-in-depth measure, administrators should populate the trustedOrigins configuration array. This restricts the domains that the application will interact with during cross-origin scenarios and redirect sequences. If immediate patching is not technically feasible, security teams should implement WAF rules to inspect and validate the Host header on inbound requests to the /api/*/forgot-password endpoints.

Official Patches

Payload CMSPayload Release v3.79.1

Fix Analysis (2)

Technical Appendix

CVSS Score
9.1/ 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Affected Systems

Payload CMSpayload package@payloadcms/graphql package

Affected Versions Detail

Product
Affected Versions
Fixed Version
payload
Payload CMS
< 3.79.13.79.1
@payloadcms/graphql
Payload CMS
< 3.79.13.79.1
AttributeDetail
CWE IDCWE-640
Attack VectorNetwork
CVSS Score9.1 (Critical)
Exploit StatusProof of Concept (PoC)
CISA KEVNot Listed
Affected ComponentPassword Recovery Endpoints

MITRE ATT&CK Mapping

T1190Exploit Public-Facing Application
Initial Access
T1566Phishing
Initial Access
T1531Account Access Removal
Impact
CWE-640
Weak Password Recovery Mechanism for Forgotten Password

The application contains vulnerabilities in the password recovery process allowing the manipulation of reset links and query logic bypasses.

Vulnerability Timeline

Fixes for timezone defaults and join table isolation committed.
2026-03-04
Fix for contains operator partial matching on hasMany fields committed.
2026-03-06
Final hardening for URL validation and joined collection access control committed.
2026-03-10
Version 3.79.1 released.
2026-03-16
CVE-2026-34751 published.
2026-04-01

References & Sources

  • [1]GitHub Advisory GHSA-hp5w-3hxx-vmwf
  • [2]Payload Release v3.79.1
  • [3]Commit fba24380: Fix contains operator on hasMany select fields
  • [4]Commit fe36dded: Correct query limit on polymorphic joins

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•30 minutes ago•CVE-2026-85024
5.9

CVE-2026-85024: Denial of Service via Uncaught Exception in undici WebSocket Client

A high-severity Denial of Service (DoS) vulnerability exists in the undici WebSocket client implementation when processing compressed frames. The vulnerability is caused by a race condition where event listeners, including error handlers, are stripped from the active zlib stream during cleanup before the stream is fully terminated, leading to an unhandled exception.

Alon Barad
Alon Barad
1 views•7 min read
•about 2 hours ago•GHSA-6VJ9-MWQ6-2F5V
5.9

GHSA-6VJ9-MWQ6-2F5V: Cross-Tenant SMTP Credential Disclosure via Shared-State DNS Cache Pollution in Nodemailer

Nodemailer versions 5.0.0 up to 10.0.1 are vulnerable to process-global state contamination inside the DNS caching subsystem. When SMTPS connections are established in a multi-tenant Node.js process targeting a shared gateway, a lower-privilege attacker can seed the global DNS cache with a malicious TLS servername. When a victim subsequently resolves the same gateway host, Nodemailer retrieves the polluted servername, overwrites the victim's connection settings, redirects the TLS session to the attacker's virtual host, and transmits the victim's cleartext SMTP credentials directly to the attacker.

Alon Barad
Alon Barad
6 views•7 min read
•about 3 hours ago•CVE-2026-83557
5.6

CVE-2026-83557: Polymorphic Deserialization Bypass in FasterXML jackson-databind via java.lang.Comparable

An incomplete denylist vulnerability in FasterXML jackson-databind's DefaultBaseTypeLimitingValidator allows unauthenticated remote attackers to bypass polymorphic type limitations. By declaring properties of type java.lang.Comparable, attackers can instantiate arbitrary Comparable subclasses on the classpath, leading to path traversal, local file access, or application-specific state manipulation.

Alon Barad
Alon Barad
5 views•6 min read
•about 4 hours ago•CVE-2026-101914
6.5

CVE-2026-101914: Authorization Bypass via Case-Insensitive Path Matching in @grpc/grpc-js-xds

An authorization bypass vulnerability exists in the @grpc/grpc-js Node.js package (specifically within the xDS plugin wrapper @grpc/grpc-js-xds) due to a logical error in its Role-Based Access Control (RBAC) path matching component. When case-insensitive path matching is enabled, the matching logic performs a prefix comparison using the startsWith method instead of a strict equality comparison. This logic flaw allows unauthenticated or low-privilege clients with access to a shorter path to gain unauthorized access to longer, more privileged method names that share the same prefix.

Amit Schendel
Amit Schendel
6 views•6 min read
•about 8 hours ago•CVE-2026-61834
4.3

CVE-2026-61834: Prototype Pollution and Mutation of Inherited Built-in Method Objects in scim-patch

A vulnerability in the scim-patch library allows authenticated users to pollute the global JavaScript execution environment. By transmitting a SCIM PATCH operation targeting inherited built-in methods, such as toString, valueOf, or hasOwnProperty, attackers bypass blocklist filters and mutate global prototype objects. This flaw occurs due to the library relying on standard prototype lookup and the 'in' operator during path-resolution and assignment, resolving to shared native functions instead of treating them as missing own-properties.

Alon Barad
Alon Barad
7 views•6 min read
•about 9 hours ago•GHSA-456V-XQ2P-R4CJ
7.8

GHSA-456V-XQ2P-R4CJ: OS Command Injection in code-ollama grep_search Tool

An OS command injection vulnerability in the grep_search tool of the code-ollama package allows remote code execution. This vulnerability is triggered when a local client executes the CLI against a malicious or compromised Ollama server. Due to grep_search being classified as a read-only tool, the CLI executes it automatically in Plan mode without human-in-the-loop validation, leading to zero-interaction local system compromise.

Amit Schendel
Amit Schendel
8 views•5 min read