CVE-2026-27567
CVE-2026-27567 is a medium-severity vulnerability in Payloadcms Payload with a CVSS 3.x base score of 6.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-918.
Key facts
- Severity: Medium (CVSS 3.x base score 6.5)
- EPSS exploit prediction: 0% (21st percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2026-8467
- Weakness: CWE-918
- Affected product: Payloadcms Payload
- Published:
- Last modified:
Description
Payload is a free and open source headless content management system. Prior to 3.75.0, a Server-Side Request Forgery (SSRF) vulnerability exists in Payload's external file upload functionality. When processing external URLs for file uploads, insufficient validation of HTTP redirects could allow an authenticated attacker to access internal network resources. The Payload environment must have at least one collection with `upload` enabled and a user who has `create` access to that upload-enabled collection in order to be vulnerable. An authenticated user with upload collection write permissions could potentially access internal services. Response content from internal services could be retrieved through the application. This vulnerability has been patched in v3.75.0. As a workaround, one may mitigate this vulnerability by disabling external file uploads via the `disableExternalFile` upload collection option, or by restricting `create` access on upload-enabled collections to trusted users only.
Frequently asked questions
- What is CVE-2026-27567?
- Payload is a free and open source headless content management system. Prior to 3.75.0, a Server-Side Request Forgery (SSRF) vulnerability exists in Payload's external file upload functionality. When processing external URLs for file uploads, insufficient validation of HTTP redirects could allow an authenticated attacker to access internal network resources. The Payload environment must have at least one collection with `upload` enabled and a user who has `create` access to that upload-enabled collection in order to be vulnerable. An authenticated user with upload collection write permissions could potentially access internal services. Response content from internal services could be retrieved through the application. This vulnerability has been patched in v3.75.0. As a workaround, one may mitigate this vulnerability by disabling external file uploads via the `disableExternalFile` upload collection option, or by restricting `create` access on upload-enabled collections to trusted users only.
- How severe is CVE-2026-27567?
- CVE-2026-27567 has a CVSS 3.x base score of 6.5, rated medium severity. It is exploitable over network with low attack complexity, requires high privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability none.
- Is CVE-2026-27567 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (21st percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-27567?
- CVE-2026-27567 affects Payloadcms Payload. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-27567?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- Does CVE-2026-27567 have an EU (EUVD) identifier?
- Yes. CVE-2026-27567 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2026-8467.
- When was CVE-2026-27567 published?
- CVE-2026-27567 was published on 2026-02-24 and last updated on 2026-06-17.
References
- https://github.com/payloadcms/payload/commit/1041bb6
- https://github.com/payloadcms/payload/releases/tag/v3.75.0
- https://github.com/payloadcms/payload/security/advisories/GHSA-hhfx-5x8j-f5f6
Affected products (1)
- cpe:2.3:a:payloadcms:payload:*:*:*:*:*:node.js:*:*
More vulnerabilities in Payloadcms Payload
- CVE-2026-25544 — Critical (CVSS 9.8): Payload is a free and open source headless content management system. Prior to 3.73.0, when querying JSON or richText…
- CVE-2022-27952 — Critical (CVSS 9.8): An arbitrary file upload vulnerability in the file upload module of PayloadCMS v0.15.0 allows attackers to execute…
- CVE-2026-34751 — Critical (CVSS 9.1): Payload is a free and open source headless content management system. Prior to version 3.79.1 in @payloadcms/graphql…
- CVE-2026-34748 — High (CVSS 8.7): Payload is a free and open source headless content management system. Prior to version 3.78.0 in @payloadcms/next, a…
- CVE-2026-34747 — High (CVSS 8.5): Payload is a free and open source headless content management system. Prior to version 3.79.1, certain request inputs…
- CVE-2026-34746 — High (CVSS 7.7): Payload is a free and open source headless content management system. Prior to version 3.79.1, an authenticated…
All CVEs affecting Payloadcms Payload →
Other CWE-918 (Server-Side Request Forgery (SSRF)) vulnerabilities
- CVE-2026-69502 — Critical (CVSS 10.0): Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a…
- CVE-2026-65801 — Critical (CVSS 10.0): Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges…
- CVE-2026-48331 — Critical (CVSS 10.0): Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in…
- CVE-2026-54735 — Critical (CVSS 10.0): Prebid Server is an open-source solution for running real-time advertising auctions in the cloud. Prior to version…
- CVE-2026-57106 — Critical (CVSS 10.0): Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-15409 — Critical (CVSS 10.0): A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A…
Browse all CWE-918 (Server-Side Request Forgery (SSRF)) vulnerabilities →