POCBIT

Telegram — New PoC releases & critical CVE alerts

You can join our Telegram channel to get instant updates on new PoC releases and critical CVE alerts.

Join @pocbit
Web appcritical

CVE-2026-105844 — Payload CMS Import/Export Plugin Prototype Pollution → ACL Bypass

October 7, 2026 · 97 views

Payload CMS + @payloadcms/plugin-import-export ≥3.0.0 <3.88.0: POST /api/exports/export-preview fields __proto__.overrideAccess pollutes Object.prototype via getSelect() → overrideAccess on later REST ops, unauthenticated data leak (app-dependent RCE). CWE-1321, CVSS 4.0 9.3 Critical. Fixed 3.88.0 / 4.0.0-canary.27. Python PoC: check/exploit/mass -j, hits.txt & exploited.txt.

#payload-cms#nodejs#prototype-pollution#cwe-1321#acl-bypass#unauthenticated#critical#import-export

CVE:

CVE-2026-105844

Date:

2026-10-07

Severity:

CRITICAL

Exploit source

Full PoC repository on GitHub (public).

Description

Overview

CVE-2026-105844 — Payload CMS with @payloadcms/plugin-import-export — prototype pollution (CWE-1321) leading to access-control bypass and unauthenticated API data leak (impact may extend to RCE depending on app code). CVSS 4.0 9.3 Critical.

| | | |---|---| | Affected | Payload / plugin ≥ 3.0.0 < 3.88.0; canary < 4.0.0-canary.27 | | Fixed | 3.88.0, 4.0.0-canary.27 | | Endpoint | POST /api/exports/export-preview (default exports slug; override with --exports-slug) | | Trigger | fields path __proto__.overrideAccess via vulnerable getSelect() |

Only sites with the Import/Export plugin enabled are in scope. Payload alone is not sufficient.

PoC page: https://pocbit.org/pocs/cve-2026-105844

GitHub: murrez/CVE-2026-105844

CVE.org: CVE-2026-105844

GHSA: GHSA-qf28-8hc6-vwrp

Mechanism (summary)

  1. handlePreview calls getSelect(fields) when fields is non-empty.
  2. Vulnerable getSelect walks dot-paths; segment __proto__ attaches to Object.prototype.
  3. __proto__.overrideAccess sets Object.prototype.overrideAccess = true.
  4. Later Payload merges inherit overrideAccess: true → unauthenticated REST reads/writes.

Patched code rejects __proto__, constructor, prototype and returns Invalid field path.

Bundled tool (Python 3)

Download cve-2026-105844.py — writes poc.py, requirements.txt, targets.example.txt.

python cve-2026-105844.py
pip install -r requirements.txt

python poc.py -u https://cms.example --mode check
python poc.py -u https://cms.example --mode check --aggressive
python poc.py -u https://cms.example --mode exploit --collection users
python poc.py --list targets.example.txt --mode check -j 20
python poc.py --list hits.txt --mode exploit -j 10

Check: endpoint reachable + pollution path not blocked. --aggressive: compares GET /api/{collection} doc count before/after pollution.

Exploit: pollute → GET /api/users (or --collection) → docs leak.

Outputs: hits.txt, exploited.txt, cve_2026_105844_*.jsonl.

Options: --exports-slug, --collection (repeatable), --pollution-path.

Discovery hints (your assets only)

Tier 1 Payload fingerprints, tier 2 import-export hints (plugin-import-export, export-preview, /admin/collections/exports). Always confirm with check — patched versions and disabled plugins false-negative.

Remediation

  1. Upgrade to Payload 3.88.0+ (or 4.0.0-canary.27+).
  2. Until patched: disable import-export plugin or block /api/*/export-preview at the edge.

Legal and ethical use

Authorized security testing only.

References

Related PoCs

Same platform, vendor, or tags — explore more write-ups on Pocbit.

Browse full PoC archive →