Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-fx49-4h83-wjv9 | Payload didn't enforce field-level password update restrictions |
Tue, 06 Oct 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, the server fails to enforce a field-level access.update restriction on the password field of an authentication collection. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34. | |
| Title | Payload: Field-level password update restrictions were not enforced | |
| Weaknesses | CWE-284 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-06T17:18:56.091Z
Reserved: 2026-10-05T23:06:29.748Z
Link: CVE-2026-105855
No data.
Status : Received
Published: 2026-10-06T17:17:21.430
Modified: 2026-10-06T17:17:21.430
Link: CVE-2026-105855
No data.
OpenCVE Enrichment
No data.
-
CWE-284
Improper Access Control
Github GHSA