CVE-2026-34749 Details
Description
Payload is a free and open source headless content management system. Prior to version 3.79.1, a Cross-Site Request Forgery (CSRF) vulnerability exists in the authentication flow. Under certain conditions, the configured CSRF protection could be bypassed, allowing cross-site requests to be made. This issue has been patched in version 3.79.1.
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in Payload CMS versions prior to 3.79.1. This vulnerability allows for the bypassing of CSRF protection under certain conditions, enabling cross-site requests to be made during the authentication process. The issue arises when the 'serverURL' is configured, creating a potential risk for applications using affected versions of Payload CMS.
Users are advised to upgrade to Payload CMS version 3.79.1 or later, where this vulnerability has been patched. If an immediate upgrade is not possible, setting 'cookies.sameSite' to 'Strict' can help prevent the session cookie from being sent cross-site, although this will require users to re-authenticate when following external links.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 2, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/payloadcms/payload/releases/tag/v3.79.1 | [email protected] | ProductRelease Notes |
| https://github.com/payloadcms/payload/security/advisories/GHSA-p6mr-xf3r-ghq4 | [email protected] | MitigationVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-352 | Cross-Site Request Forgery (CSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| payloadcms payload | < 3.79.1 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 13, 2026 | Initial Analysis | [email protected] |
| Apr 1, 2026 | New CVE Received | [email protected] |