CVE-2026-39397Disclosure(delmaredigital / payload-puck)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch delmaredigital payload-puck systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

@delmaredigital/payload-puck is a PayloadCMS plugin for integrating Puck visual page builder. Prior to 0.6.23, all /api/puck/* CRUD endpoint handlers registered by createPuckPlugin() called Payload's local API with the default overrideAccess: true, bypassing all collection-level access control. The access option passed to createPuckPlugin() and any access rules defined on Puck-registered collections were silently ignored on these endpoints. This vulnerability is fixed in 0.6.23.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • payload-puck

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 6 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 3 mentions (2026-04-08); latest day: 1
  • 6 total mentions across 3 days

Affected systems

Products
payload-puck

Deep dive

Activity timeline6 mentions / 3d
01223Mentions · 2026-04-07: 2Mentions · 2026-04-08: 3Mentions · 2026-04-09: 1PoC Mentioned / Linked · 2026-04-07: 1Patch / Workaround · 2026-04-07: 1Patch / Workaround · 2026-04-08: 1Patch / Workaround · 2026-04-09: 1Technical Details · 2026-04-07: 2Technical Details · 2026-04-08: 3Technical Details · 2026-04-09: 104-0704-0804-09
Signal classification3 categories
Disclosure
350.0%
Patch
233.3%
PoC
116.7%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-04-072
Patch1PoC1
2026-04-083
Disclosure2Patch1
2026-04-091
Disclosure1
Full discourse6 posts
  • PulsePatch.io@pulsepatchio
    Disclosure

    A critical authorization bypass (CVE-2026-39397) affects `delmaredigital/payload-puc`, allowing unauthenticated access to `Puck` collections. Implement robust authorization on `/api/puck/*` endpoints. #CVE #AuthBypass #Infosec https://www.pulsepatch.io/posts/cve-2026-39397-payload-puc-unauthenticated-access

    Post summary

    The tweet announces CVE‑2026‑39397 in `payload‑puc`, a critical authorization bypass that allows unauthenticated access to Puck collections, and recommends enforcing authorization on `/api/puck/*` endpoints.

    0000037
    11 followersView on X
  • Vulert@vulert_official
    Patch

    🚨 Critical @delmaredigital/payload-puc flaw: CVE-2026-39397 This issue could allow unauthenticated access to sensitive CRUD operations. Update to v0.6.23 now or apply the workaround. 🔗 https://vulert.com/vuln-db/CVE-2026-39397 #CyberSecurity #PayloadPUC #CVE202639397 #Vulert https://t.co/eCCGU8zKHr

    Post summary

    The tweet announces CVE‑2026‑39397, outlines an unauthenticated CRUD access vulnerability, and urges users to update to v0.6.23 or apply the provided workaround.

    0000033
    124 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-39397 Unauthorized API Access in Payload Puck Plugin Versions Below 0.6.23 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-39397

    Post summary

    The post announces the discovery of an unauthorized API access vulnerability in Payload Puck plugin versions below 0.6.23, without mentioning PoCs, exploits, or mitigation.

    0000049
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-39397 @delmaredigital/payload-puck is a PayloadCMS plugin for integrating Puck visual page builder. Prior to 0.6.23, all /api/puck/* CRUD endpoint handlers registered by cr… https://www.cve.org/CVERecord?id=CVE-2026-39397

    Post summary

    The text announces CVE-2026-39397 affecting the PayloadCMS plugin payload-puck, noting a vulnerability with CRUD endpoint handlers prior to version 0.6.23.

    00000170
    57.0K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-39397: CRITICAL] Update now: Prior version 0.6.23 of PayloadCMS Plugin for Puck visual page builder had a critical vulnerability, giving bypass access control. Ensure you are protected with the lat...#cve,CVE-2026-39397,#cybersecurity https://cvefind.com/CVE-2026-39397

    Post summary

    The message announces that the critical CVE-2026-39397 affecting the PayloadCMS Plugin for Puck visual page builder allows an access control bypass, and urges users to apply the latest patch to mitigate the issue.

    0000050
    619 followersView on X
  • 0day Signal@0dayPublishing
    PoC

    🚨 CVE-2026-39397: @delmaredigital/payload-puc is m... Complete auth bypass in PayloadCMS Puck plugin - overrideAccess:true nukes all collection ACLs, turning CRUD endpoints ... https://zerodaysignal.com/vulnerability/CVE-2026-39397 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post discloses a CVE‑2026‑39397 flaw in the PayloadCMS Puck plugin that allows an auth bypass by exploiting overrideAccess:true, wiping ACLs and exposing CRUD endpoints, and it references a PoC repository and a zero‑day advisory link.

    0000070
    204 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdelmaredigitalpayload-puck-node.js-

Explore more