
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-34751 is a pre-authentication account takeover vulnerability in Payload CMS caused by unvalidated input in the password recovery endpoints. An unauthenticated attacker can exploit improper URL construction and insufficient input validation in the forgot-password flow to perform actions on behalf of any user who initiates a password reset. The vulnerability affects all Payload npm packages (payload and @payloadcms/graphql) below version 3.79.1 that use any auth-enabled collection with the built-in forgot-password functionality. It was published on March 30, 2026, and carries a CVSS v3.1 base score of 9.1 (Critical) (GitHub Advisory, Payload Security Advisory).
The root cause is classified under CWE-472 (External Control of Assumed-Immutable Web Parameter) and CWE-640 (Weak Password Recovery Mechanism for Forgotten Password). The vulnerability stems from the password recovery flow failing to adequately validate inputs that are assumed to be server-controlled — such as URL construction parameters — allowing an attacker to inject or manipulate values that influence the reset flow. Because no authentication or user interaction is required, an attacker can remotely trigger the flaw by crafting requests to the forgot-password endpoint and injecting parameters that redirect or hijack the password reset token delivery or consumption. The fix in v3.79.1 hardened both input validation and URL construction logic in the recovery flow (GitHub Advisory, Payload Security Advisory).
Successful exploitation allows an unauthenticated attacker to take over user accounts by performing unauthorized actions on behalf of any user who initiates a password reset, resulting in high confidentiality and integrity impact. Attackers could gain full access to victim accounts, read sensitive user data, modify account credentials or associated records, and potentially escalate privileges if administrative accounts are targeted. Availability is not directly impacted, but account takeover of privileged users could enable broader compromise of the Payload CMS instance and its underlying data (GitHub Advisory, Feedly).
As of the time of publication, there is no public proof-of-concept exploit code and no confirmed evidence of in-the-wild exploitation (Feedly). The vulnerability requires no privileges and no user interaction from the attacker's side, though it is contingent on a legitimate user initiating a password reset. The EPSS score is approximately 0.10% (28th percentile), indicating a currently low but non-negligible probability of exploitation in the near term (GitHub Advisory). No threat actor attribution or CISA KEV catalog listing has been identified at this time.
forgot-password functionality are active.POST /api/<collection>/forgot-password) for a known or guessed user email address to initiate the password recovery flow.POST requests to /api/<collection>/forgot-password endpoints, especially from a single IP or with anomalous parameter values; requests containing unexpected URL or redirect parameters in the password recovery flow.The vendor has released a patch in Payload v3.79.1, which hardens input validation and URL construction in the password recovery flow for both the payload and @payloadcms/graphql npm packages. There are no complete workarounds available — upgrading to v3.79.1 or later is the only effective remediation. Organizations should prioritize patching all instances running Payload versions below 3.79.1 that have auth-enabled collections using the built-in forgot-password functionality (Payload Security Advisory, v3.79.1 Release).
The vulnerability was credited to researcher wsk3r and published by Payload maintainer denolfe on March 30, 2026 (GitHub Advisory). Coverage appeared on The Hacker Wire and several CVE aggregator platforms shortly after disclosure (Feedly). No significant broader community controversy or vendor dispute has been noted.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."