Executive brief
Payload CMS is a popular headless CMS platform used to manage content and user authentication for web applications. A cross-collection access control vulnerability allows authenticated users to read and delete preferences from other user accounts when multiple auth collections are configured with auto-incrementing numeric IDs. This could enable account takeover or data destruction across user groups in multi-tenant environments.
Technical details
The vulnerability is an Insecure Direct Object Reference (IDOR) affecting the payload-preferences internal collection. The root cause is insufficient access control validation in multi-auth collection environments using Postgres or SQLite with default serial/auto-increment IDs. An authenticated user from one auth collection can reference and manipulate preference records belonging to users in different collections by guessing or iterating numeric IDs. Attack requires multiple auth collections, Postgres/SQLite with serial IDs, and users with matching numeric IDs across collections. The attacker needs network access and valid authentication to one collection but gains read/delete capabilities across collections. The vulnerability has been patched in v3.74.0 and does not affect MongoDB-backed deployments or UUID-based ID schemes.
Affected products
- Payload Payload CMS < 3.74.0
Timeline
- 2026-02-05: disclosed
- 2026-02-05: patched: v3.74.0