Password Hijack in the Modern Stack: Payload CMS Patches Critical 9.1 CVSS Reset Flaw
ID: 5a8bc9ab-71b2-5500-a7bc-01e74c908bca
STIX ID: report--5a8bc9ab-71b2-5500-a7bc-01e74c908bca
Feed Name: securityonline.info
Threat Score
A critical vulnerability (CVE-2026-34751, CVSS 9.1) was discovered in the Payload framework's password recovery endpoints that can enable unauthenticated attackers to hijack the reset process and act on behalf of users; Payload users running versions prior to v3.79.1 with auth-enabled collections using the built-in forgot-password feature are urged to upgrade immediately to v3.79.1, which introduces stricter input validation and hardened reset-link construction.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
