PT-2026-31018 · Unknown+1 · Payloadcms+1

Dag-Rui

·

Published

2026-04-07

·

Updated

2026-04-09

·

CVE-2026-39397

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions @delmaredigital/payload-puck versions prior to 0.6.23
Description The @delmaredigital/payload-puck plugin for PayloadCMS, a visual page builder integration, had a critical issue where access control was bypassed. Specifically, all CRUD endpoint handlers registered by createPuckPlugin() called Payload's local API with overrideAccess: true, ignoring collection-level access controls. The access option passed to createPuckPlugin() and any access rules defined on Puck-registered collections were also ignored on these endpoints.
Recommendations Update to version 0.6.23 or later.

Exploit

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-39397
GHSA-65W6-PF7X-5G85

Affected Products

@Delmaredigital/Payload-Puck
Payloadcms