OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2026-105853: Payload: Token refresh and password reset responses may expose restricted user fields

GitHub Advisories · officialPublished Oct 6, 2026Risk 37/100

## Impact Token refresh and password reset responses could return fields that the requesting user did not have access to. You are affected if: - An authentication collection contains hidden or read-restricted fields. ## Patches Authentication responses now apply field access and hidden-field filtering before returning user documents. Full user documents remain available server-side for access control. Users should upgrade Payload packages to `>= 3.90.0` or `>= 4.0.0-canary.34`. Custom authentication strategies remain responsible for filtering user documents returned through custom responses. ## Workarounds There is no complete workaround. Users should upgrade Payload packages to `>= 3.90.0` or `>= 4.0.0-canary.34`.

Upgrade affected packages to a patched version: payload 3.90.0, payload 4.0.0-canary.34.

Vendor
Not specified
Product
payload
Exploitation
none known
Evidence
official

This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source