Payload Import/Export Pollution (CVE-2026-105844): __proto__.overrideAccess ACL Bypass
Admin · October 8, 2026 · 6 views
Headless CMS, real ACL bypass
Payload CMS with @payloadcms/plugin-import-export enabled exposes a preview export API. CVE-2026-105844 is prototype pollution (CWE-1321) on fields passed into vulnerable getSelect()—CVSS 4.0 9.3 Critical, no authentication required for the trigger path when the plugin is active.
Polluting Object.prototype.overrideAccess causes later Payload REST merges to inherit overrideAccess: true, bypassing access control and leaking docs from collections such as users. Application-dependent chains may worsen impact; the catalog PoC focuses on check, exploit, and mass verification.
Mechanism and tooling: CVE-2026-105844 on pocbit.org. Repository: murrez/CVE-2026-105844. Vendor: GHSA-qf28-8hc6-vwrp.
| | |
|---|---|
| Affected | Payload / plugin ≥ 3.0.0 < 3.88.0; canary < 4.0.0-canary.27 |
| Fixed | 3.88.0, 4.0.0-canary.27 |
| Endpoint | POST /api/exports/export-preview |
Payload alone is not enough—only instances with Import/Export installed and enabled.
Mechanism in plain language
- Attacker POSTs
export-previewwith afieldsobject using path__proto__.overrideAccess. - Vulnerable
getSelectwalks dot segments and attaches properties toObject.prototype. - Subsequent API handlers merge options from
{}and pick upoverrideAccess: true. - GET
/api/users(or other collections) returns data that should require auth.
Patched releases reject __proto__, constructor, and prototype with Invalid field path.
Defender checklist
| # | Action | Detail |
|---|--------|--------|
| 1 | Confirm plugin-import-export in use | Admin UI / package.json on deploy repo |
| 2 | Upgrade to Payload 3.88.0+ (or fixed canary) | Lockfile audit in CI |
| 3 | Until patched | Disable plugin or block export-preview at reverse proxy/WAF |
| 4 | Post-incident | Assume user PII in leaked collections; notify per policy |
| 5 | Aggressive check | Compare collection doc counts before/after pollution in lab only |
Cross-read: API security — JWT/OAuth mistakes, how to prioritize critical CVEs, supply chain security.
Discovery tiers (your assets only)
Tier 1: Payload admin/login HTML, payload-token, @layer payload-default. Tier 2: plugin-import-export, export-preview, collections/exports. Tier 1 finds CMS hosts; tier 2 narrows to exploitable installs—always python poc.py --mode check.
Patch validation in a lab
- Staging Payload 3.x with import-export plugin on a vulnerable patch level.
- Run PoC check, then exploit --collection users against the lab URL.
- Upgrade to 3.88.0+; confirm
Invalid field pathor failed pollution.
See safe PoC lab setup.
FAQ
We run Payload but not import-export—safe?
If the plugin is absent or disabled, the vulnerable route should not register—still upgrade core and audit dependencies.
Can WAF block __proto__ forever?
Temporary rule on export-preview body helps during maintenance; vendor fix is required.
Bottom line
CVE-2026-105844 shows that Node object merging and plugin preview endpoints are security boundaries. Upgrade Payload, disable unused plugins, and treat export-preview like an admin-only surface—even when marketing calls the CMS “headless.”