CVE-2026-25544: Critical Payload CMS SQLi (CVSS 9.8) Exposes Admin Tokens
ID: cae5b7df-5a1d-5bc1-a99c-3b20246b0a5f
STIX ID: report--cae5b7df-5a1d-5bc1-a99c-3b20246b0a5f
Feed Name: securityonline.info
A critical vulnerability (CVE-2026-25544, CVSS 9.8) in Payload CMS versions prior to v3.73.0 allows unauthenticated blind SQL injection via Drizzle-based PostgreSQL and SQLite adapters when public-readable json or richText fields exist; attackers can exfiltrate sensitive data (including emails and password reset tokens) and perform full administrative takeover. The issue is fixed in Payload v3.73.0 and a temporary mitigation is to set access.read to false on affected fields until patched.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
