CVE-2026-105853: Payload: Token refresh and password reset responses may expose restricted user fields
Impact
Token refresh and password reset responses could return fields that the requesting user did not have access to.
You are affected if:
- An authentication collection contains hidden or read-restricted fields.
Patches
Authentication responses now apply field access and hidden-field filtering before returning user documents. Full user documents remain available server-side for access control.
Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.
Custom authentication strategies remain responsible for filtering user documents returned through custom responses.
Workarounds
There is no complete workaround. Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.
Other sources
Payload is a free and open source headless content management system. In versions from 3.0.0 before 3.90.0 and canary versions before 4.0.0-canary.34, token refresh responses and password reset responses can independently return hidden or read-restricted fields that the requesting user cannot access. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/payloadto a version that resolves this vulnerability.Fixed in 4.0.0-canary.34 - Upgrade
Upgrade
npm/payloadto a version that resolves this vulnerability.Fixed in 3.90.0 - Upgrade
Upgrade
Payloadto a version that resolves this vulnerability.Fixed in 3.90.0 - Upgrade
Upgrade
Payloadto a version that resolves this vulnerability.Fixed in 4.0.0-canary.34
Event History
Frequently Asked Questions
Which deployments are affected?
Affected deployments have an authentication collection with fields that are hidden or restricted by read access. The issue applies to Payload versions from 3.0.0 before 3.90.0 and canary versions before 4.0.0-canary.34.
What does an attacker need to do to obtain restricted fields?
The exposure occurs through token refresh and password reset responses. A requesting user can receive hidden or read-restricted fields that they would not otherwise be permitted to access.
Are custom authentication strategies covered by the fix?
No. Custom authentication strategies remain responsible for filtering user documents returned in their custom responses.
What should be done if patching cannot happen immediately?
There is no complete workaround. Upgrade Payload to version 3.90.0 or later, or to 4.0.0-canary.34 or later.