
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-34750 is a path traversal vulnerability (CWE-22) in Payload CMS's client-upload signed-URL endpoints affecting the @payloadcms/storage-azure, @payloadcms/storage-gcs, @payloadcms/storage-r2, and @payloadcms/storage-s3 npm packages. The flaw allows authenticated attackers to craft malicious filenames that escape the intended storage location when uploading files via signed URLs. All Payload CMS installations using these storage adapters at versions prior to 3.78.0 are affected. The vulnerability was published on March 30, 2026, and assigned CVE-2026-34750 on April 1, 2026, with a CVSS v3.1 base score of 6.5 (Medium) (Github Advisory, Payload Advisory).
The root cause is insufficient input sanitization (CWE-22) in the filename handling logic of client-upload signed-URL endpoints across all four supported cloud storage adapters (S3, GCS, Azure Blob Storage, and Cloudflare R2). When a client requests a signed upload URL, the filename supplied by the user is not properly validated or sanitized before being used to construct the storage path, enabling path traversal sequences (e.g., ../, URL-encoded variants, or alternate slash encodings) to resolve to locations outside the intended storage directory. Exploitation requires the attacker to have low-privilege authenticated access to the upload endpoint and no user interaction. No public proof-of-concept code has been identified at this time (Github Advisory, Payload Advisory).
Successful exploitation allows an authenticated attacker to upload files to unintended locations within the cloud storage backend, potentially overwriting existing files in restricted directories or placing malicious content in sensitive paths. The primary impact is to integrity (rated High), as confidentiality and availability are not directly affected by this vulnerability. In environments where multiple users have upload capabilities, this could be leveraged to corrupt application data, overwrite configuration or static assets, or disrupt the integrity of the file storage system (Github Advisory, Feedly).
There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept exploit at this time. The EPSS score is approximately 0.028% (8th percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires low-privilege authenticated access, which limits the attack surface compared to unauthenticated vulnerabilities, but environments with broad user upload permissions remain at elevated risk (Github Advisory, Feedly).
@payloadcms/storage-s3, @payloadcms/storage-gcs, @payloadcms/storage-azure, or @payloadcms/storage-r2) with client-upload signed-URL endpoints exposed.../../restricted-directory/malicious-file.ext, URL-encoded variants (%2e%2e%2f), or alternate encodings to bypass any basic filtering.../, %2e%2e%2f, %2f, or double-encoded variants) in filename parameters; signed URL requests resolving to storage paths outside the expected upload directory..., %2e, or slash-encoded characters; signed URL generation events for paths outside the configured storage prefix.Upgrade all affected Payload CMS storage adapter packages to version 3.78.0 or later: @payloadcms/storage-azure, @payloadcms/storage-gcs, @payloadcms/storage-r2, and @payloadcms/storage-s3. Version 3.78.0 introduces hardened filename validation for client uploads. As an interim workaround for organizations unable to upgrade immediately, restrict access to client-upload signed-URL endpoints to trusted users only, and implement additional server-side filename validation as a defense-in-depth measure. Monitor cloud storage locations for suspicious files or unauthorized access patterns (Github Advisory, Payload Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."