CVE-2026-59965
Payload Plugins is a collection of plugins designed to enhance Payload CMS. In 0.7.0, @jhb.software/payload-alt-text-plugin exposes POST /api/alt-text-plugin/generate and POST /api/alt-text-plugin/bulk with a default guard that accepts any authenticated user, while alt-text/src/endpoints/generateAltText.ts and alt-text/src/endpoints/bulkGenerateAltTexts.ts call req.payload.findByID and req.payload.update without overrideAccess: false. Payload therefore defaults overrideAccess to true and skips the target collection's read and update access functions.
Leer descripción completaMostrar menos
An authenticated low-privilege user can supply id, collection, locale, and update values to read arbitrary protected upload documents and overwrite their alt and keywords fields, even when the collection permits those operations only to administrators. A control Local API call with overrideAccess: false is denied, confirming that the plugin endpoint bypasses otherwise effective collection rules. This vulnerability is fixed in 0.8.0.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
- Puntuación base: 7.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.38%
- Percentil entre todas las CVEs puntuadas: 29
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1210Exploitation of Remote Serviceslateral movement85 % - Impacto principal
T1078Valid Accountsstealth · persistence · privilege escalation · initial access80 % - Impacto secundario
T1565.001Stored Data Manipulationimpact75 %
Usuario autenticado (PR:L) explota endpoints de API sin validación de permisos (CWE-863) para leer documentos protegidos y modificar campos alt/keywords; escalada de privilegios desde usuario bajo a capacidades administrativas.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (2)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-863
Referencias
- https://github.com/jhb-software/payload-plugins/commit/e39634868ce13a414e2981e219befc58101654d3
- https://github.com/jhb-software/payload-plugins/pull/159
- https://github.com/jhb-software/payload-plugins/releases/tag/alt-text@0.8.0
- https://github.com/jhb-software/payload-plugins/security/advisories/GHSA-4qpv-39hg-f7fx
- https://github.com/jhb-software/payload-plugins/security/advisories/GHSA-4qpv-39hg-f7fx
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-59965",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-59965",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-09-17T15:27:52.534385Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.1,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 4.2,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "security-advisories@github.com",
"affectedData": [
{
"vendor": "jhb-software",
"product": "payload-plugins",
"versions": [
{
"status": "affected",
"version": "< 0.8.0"
}
]
},
{
"vendor": "@jhb.software",
"product": "payload-alt-text-plugin",
"versions": [
{
"status": "affected",
"version": "< 0.8.0"
}
]
}
]
}
],
"published": "2026-09-15T16:17:17.110",
"references": [
{
"url": "https://github.com/jhb-software/payload-plugins/commit/e39634868ce13a414e2981e219befc58101654d3",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/jhb-software/payload-plugins/pull/159",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/jhb-software/payload-plugins/releases/tag/alt-text@0.8.0",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/jhb-software/payload-plugins/security/advisories/GHSA-4qpv-39hg-f7fx",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/jhb-software/payload-plugins/security/advisories/GHSA-4qpv-39hg-f7fx",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"description": [
{
"lang": "en",
"value": "CWE-863"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Payload Plugins is a collection of plugins designed to enhance Payload CMS. In 0.7.0, @jhb.software/payload-alt-text-plugin exposes POST /api/alt-text-plugin/generate and POST /api/alt-text-plugin/bulk with a default guard that accepts any authenticated user, while alt-text/src/endpoints/generateAltText.ts and alt-text/src/endpoints/bulkGenerateAltTexts.ts call req.payload.findByID and req.payload.update without overrideAccess: false. Payload therefore defaults overrideAccess to true and skips the target collection's read and update access functions. An authenticated low-privilege user can supply id, collection, locale, and update values to read arbitrary protected upload documents and overwrite their alt and keywords fields, even when the collection permits those operations only to administrators. A control Local API call with overrideAccess: false is denied, confirming that the plugin endpoint bypasses otherwise effective collection rules. This vulnerability is fixed in 0.8.0."
}
],
"lastModified": "2026-09-30T17:51:56.193",
"sourceIdentifier": "security-advisories@github.com"
}