CVE-2026-105847: Payload: Polymorphic join queries could disclose hidden fields
Impact
A user with query access could use polymorphic join filters to infer hidden or read-restricted field values, including password-reset tokens.
You are affected if:
- You use an affected Payload version. - Users can query a collection with a polymorphic join to sensitive fields.
Patches
Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.
Workarounds
There is no complete workaround. Restricting read access to sensitive collections reduces exposure but does not replace upgrading.
Other sources
Payload is a free and open source headless content management system. In versions from 3.0.0 before 3.90.0 and canary versions before 4.0.0-canary.34, a user who can query a collection with a polymorphic join to sensitive fields can infer hidden or read-restricted values, including password-reset tokens, through polymorphic join filters. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/payloadto a version that resolves this vulnerability.Fixed in 4.0.0-canary.34 - Upgrade
Upgrade
npm/payloadto a version that resolves this vulnerability.Fixed in 3.90.0 - Upgrade
Upgrade
Payloadto a version that resolves this vulnerability.Fixed in 3.90.0 - Upgrade
Upgrade
Payloadto a version that resolves this vulnerability.Fixed in 4.0.0-canary.34 - Compensating control
Restrict read access to sensitive collections to reduce exposure to polymorphic join queries.
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Payload versions from 3.0.0 before 3.90.0 and 4.0.0 canary versions before 4.0.0-canary.34 are affected. Exposure requires users who can query a collection that has a polymorphic join to sensitive fields.
What level of access does an attacker need?
An attacker needs query access to a relevant collection. They can use polymorphic join filters to infer values from fields that are hidden or otherwise read-restricted, including password-reset tokens.
What should be done if an immediate upgrade is not possible?
There is no complete workaround. Restrict read access to sensitive collections to reduce exposure, but upgrade Payload packages to 3.90.0 or later, or 4.0.0-canary.34 or later, as soon as possible.