PT-2026-106783 · Pyload · Pyload
CVE-2026-105851
·
Published
2026-10-06
·
Updated
2026-10-07
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:N |
Name of the Vulnerable Software and Affected Versions
Payload versions 3.0.0 through 3.89.9
Payload versions prior to 4.0.0-canary.34
Description
An access-control bypass exists in the duplicate operation, which allows the copying of values from a source document even if a field is hidden or if the
access.read or access.create rules reject the value for the caller. The disableDuplicate setting does not prevent this behavior.Recommendations
Update to version 3.90.0.
Update to version 4.0.0-canary.34.
Exploit
Fix
Incorrect Authorization
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pyload