Executive brief
Payload is a popular headless CMS used to manage content and authentication for web applications. A vulnerability in its password reset functionality allows unauthenticated attackers to take over any user account that initiates a password reset, compromising user data and account security without requiring any special privileges or user interaction.
Technical details
The vulnerability is a parameter injection flaw (CWE-472) in Payload's password recovery endpoints that stems from insufficient input validation and insecure URL construction. An unauthenticated attacker can manipulate parameters in the password reset flow to perform unauthorized actions on behalf of a user, achieving pre-authentication account takeover. The attack requires no authentication, user interaction, or complex exploitation—only network access to the vulnerable endpoint. The flaw affects all versions prior to v3.79.1 in applications using auth-enabled collections with the built-in forgot-password functionality. A patch was released in v3.79.1 that hardens input validation and URL construction; users must upgrade immediately as no complete workarounds exist.
Affected products
- Payload Payload < 3.79.1
- Payload @payloadcms/graphql < 3.79.1
Timeline
- 2026-04-01: disclosed: Advisory published
- 2026-04-01: patched: Patch released in version 3.79.1