Payload CMS Duplicate Operation Leaks Hidden and Access-Restricted Fields on Auth Collections
A GitHub Security Advisory (GHSA-vc4h-q48j-5hcx, tracked as CVE-2026-105851) reports a field-level access control bypass in Payload CMS's duplicate document operation. According to the advisory, when a user duplicates a document, Payload copies field values from the source document even when a field is marked hidden, or when that field's access.read or access.create rule would otherwise reject the value for the requesting caller. Notably, the disableDuplicate collection setting — which is enabled by default on auth collections — does not prevent this behavior.
Why it matters
Auth collections (e.g., users) commonly store sensitive fields such as password hashes, roles, API keys, or other restricted attributes behind field-level access rules. If duplication bypasses those rules, a caller without permission to read or create such a field could still have its value copied into a new document, potentially exposing or propagating sensitive data they were never authorized to see or set. Any Payload deployment using field-level access control or hidden fields on auth (or other) collections should treat this as a meaningful exposure risk, particularly where the duplicate operation is reachable by lower-privileged users. The advisory lists exploit status as PoC-public, so working reproduction details may already be circulating.
What defenders should do now
- Upgrade Payload packages to
>= 3.90.0or>= 4.0.0-canary.34as soon as possible, per the advisory. - If immediate patching isn't feasible, apply the documented workaround: add a
beforeDuplicatefield hook to sensitive fields that clears the value or resets it to a safe default. - Audit collections — especially auth collections — for which roles can invoke the duplicate operation, and consider restricting or disabling duplication on collections holding sensitive or access-controlled fields until patched.
- Review application and audit logs for duplicate-operation activity on auth collections, particularly from accounts that shouldn't have visibility into the fields in question, as a hunting angle while remediation is in progress.
This is a same-day advisory and the details here reflect only what Payload has published so far; expect possible updates as the issue receives wider scrutiny. For the full technical writeup and patch guidance, see the original advisory: GHSA-vc4h-q48j-5hcx.