PulsePatch.io@pulsepatchioDisclosure
The tweet announces CVE‑2026‑39397 in `payload‑puc`, a critical authorization bypass that allows unauthenticated access to Puck collections, and recommends enforcing authorization on `/api/puck/*` endpoints.
Vulert@vulert_officialPatch
The tweet announces CVE‑2026‑39397, outlines an unauthenticated CRUD access vulnerability, and urges users to update to v0.6.23 or apply the provided workaround.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
The post announces the discovery of an unauthorized API access vulnerability in Payload Puck plugin versions below 0.6.23, without mentioning PoCs, exploits, or mitigation.
CVE@CVEnewDisclosure
The text announces CVE-2026-39397 affecting the PayloadCMS plugin payload-puck, noting a vulnerability with CRUD endpoint handlers prior to version 0.6.23.
CVEFind.com@CveFindComPatch
The message announces that the critical CVE-2026-39397 affecting the PayloadCMS Plugin for Puck visual page builder allows an access control bypass, and urges users to apply the latest patch to mitigate the issue.
0day Signal@0dayPublishingPoC
The post discloses a CVE‑2026‑39397 flaw in the PayloadCMS Puck plugin that allows an auth bypass by exploiting overrideAccess:true, wiping ACLs and exposing CRUD endpoints, and it references a PoC repository and a zero‑day advisory link.