logo

CVE-2026-25544: Critical Payload CMS SQLi (CVSS 9.8) Exposes Admin Tokens

ID: cae5b7df-5a1d-5bc1-a99c-3b20246b0a5f

STIX ID: report--cae5b7df-5a1d-5bc1-a99c-3b20246b0a5f

Feed Name: securityonline.info

Threat Score
80/100

Date Published: 2026-02-10

Date Updated: 2026-04-23

Author: Ddos

...
...

A critical vulnerability (CVE-2026-25544, CVSS 9.8) in Payload CMS versions prior to v3.73.0 allows unauthenticated blind SQL injection via Drizzle-based PostgreSQL and SQLite adapters when public-readable json or richText fields exist; attackers can exfiltrate sensitive data (including emails and password reset tokens) and perform full administrative takeover. The issue is fixed in Payload v3.73.0 and a temporary mitigation is to set access.read to false on affected fields until patched.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.