PT-2026-106785 · Pyload · Pyload
CVE-2026-105853
·
Published
2026-10-06
·
Updated
2026-10-06
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Payload versions 3.0.0 through 3.89.9
Payload versions 4.0.0-canary.0 through 4.0.0-canary.33
Description
Token refresh and password reset responses can independently return hidden or read-restricted fields that the requesting user is not authorized to access. This occurs when an authentication collection contains fields marked as hidden or restricted for reading.
Recommendations
Update Payload versions 3.0.0 through 3.89.9 to version 3.90.0 or later.
Update Payload versions 4.0.0-canary.0 through 4.0.0-canary.33 to version 4.0.0-canary.34 or later.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pyload