CVE-2026-34751 Details
Description
Payload is a free and open source headless content management system. Prior to version 3.79.1 in @payloadcms/graphql and payload, a vulnerability in the password recovery flow could allow an unauthenticated attacker to perform actions on behalf of a user who initiates a password reset. This issue has been patched in version 3.79.1 for @payloadcms/graphql and payload.
A vulnerability exists in the password recovery process of Payload CMS versions prior to 3.79.1, specifically within the @payloadcms/graphql package. This issue allows an unauthenticated attacker to perform actions on behalf of a user who has requested a password reset. The vulnerability arises from unvalidated input in the password recovery endpoints, which could be exploited to manipulate the recovery process.
Users are advised to upgrade to Payload CMS version 3.79.1 or later. Instructions for updating can be found in the release notes on the Payload CMS GitHub repository.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 4, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/payloadcms/payload/releases/tag/v3.79.1 | [email protected] | ProductRelease Notes |
| https://github.com/payloadcms/payload/security/advisories/GHSA-hp5w-3hxx-vmwf | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-472 | External Control of Assumed-Immutable Web Parameter | [email protected] |
| CWE-640 | Weak Password Recovery Mechanism for Forgotten Password | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| payloadcms payload | < 3.79.1 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 15, 2026 | Initial Analysis | [email protected] |
| Apr 1, 2026 | New CVE Received | [email protected] |