← Blog · · df00tech

Payload CMS Duplicate Operation Leaks Hidden and Access-Restricted Fields on Auth Collections

breaking ghsa npm CVE-2026-105851

A GitHub Security Advisory (GHSA-vc4h-q48j-5hcx, tracked as CVE-2026-105851) reports a field-level access control bypass in Payload CMS's duplicate document operation. According to the advisory, when a user duplicates a document, Payload copies field values from the source document even when a field is marked hidden, or when that field's access.read or access.create rule would otherwise reject the value for the requesting caller. Notably, the disableDuplicate collection setting — which is enabled by default on auth collections — does not prevent this behavior.

Why it matters

Auth collections (e.g., users) commonly store sensitive fields such as password hashes, roles, API keys, or other restricted attributes behind field-level access rules. If duplication bypasses those rules, a caller without permission to read or create such a field could still have its value copied into a new document, potentially exposing or propagating sensitive data they were never authorized to see or set. Any Payload deployment using field-level access control or hidden fields on auth (or other) collections should treat this as a meaningful exposure risk, particularly where the duplicate operation is reachable by lower-privileged users. The advisory lists exploit status as PoC-public, so working reproduction details may already be circulating.

What defenders should do now

  • Upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34 as soon as possible, per the advisory.
  • If immediate patching isn't feasible, apply the documented workaround: add a beforeDuplicate field hook to sensitive fields that clears the value or resets it to a safe default.
  • Audit collections — especially auth collections — for which roles can invoke the duplicate operation, and consider restricting or disabling duplication on collections holding sensitive or access-controlled fields until patched.
  • Review application and audit logs for duplicate-operation activity on auth collections, particularly from accounts that shouldn't have visibility into the fields in question, as a hunting angle while remediation is in progress.

This is a same-day advisory and the details here reflect only what Payload has published so far; expect possible updates as the issue receives wider scrutiny. For the full technical writeup and patch guidance, see the original advisory: GHSA-vc4h-q48j-5hcx.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.