logo

Password Hijack in the Modern Stack: Payload CMS Patches Critical 9.1 CVSS Reset Flaw

ID: 5a8bc9ab-71b2-5500-a7bc-01e74c908bca

STIX ID: report--5a8bc9ab-71b2-5500-a7bc-01e74c908bca

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-04-03

Date Updated: 2026-04-23

Author: Ddos

...
...

A critical vulnerability (CVE-2026-34751, CVSS 9.1) was discovered in the Payload framework's password recovery endpoints that can enable unauthenticated attackers to hijack the reset process and act on behalf of users; Payload users running versions prior to v3.79.1 with auth-enabled collections using the built-in forgot-password feature are urged to upgrade immediately to v3.79.1, which introduces stricter input validation and hardened reset-link construction.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.