PT-2026-6651 · Payloadcms · Pyload
S2Ongmo
·
Published
2026-02-05
·
Updated
2026-02-09
·
CVE-2026-25574
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Payload versions prior to 3.74.0
Description
Payload is a headless content management system. A cross-collection Insecure Direct Object Reference (IDOR) exists in the
payload-preferences internal collection. In multi-auth collection environments using Postgres or SQLite with default serial/auto-increment IDs, authenticated users from one auth collection can read and delete preferences belonging to users in different auth collections when their numeric IDs collide. The vulnerability affects users if multiple auth collections are configured, a Postgres or SQLite database adapter with serial/auto-increment IDs is used, and users in different auth collections have the same numeric ID. The issue does not affect users utilizing the @payloadcms/db-mongodb adapter, single auth collection environments, or Postgres/SQLite with idType: 'uuid'.Recommendations
Upgrade to version 3.74.0 or later.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pyload