Payload: Pre-Authentication Account Takeover via Parameter Injection in Password Recovery
Critical severity
GitHub Reviewed
Published
Mar 30, 2026
in
payloadcms/payload
•
Updated Apr 8, 2026
Description
Published to the GitHub Advisory Database
Apr 1, 2026
Reviewed
Apr 1, 2026
Published by the National Vulnerability Database
Apr 1, 2026
Last updated
Apr 8, 2026
Impact
A vulnerability in the password recovery flow could allow an unauthenticated attacker to perform actions on behalf of a user who initiates a password reset.
Users are affected if:
forgot-passwordfunctionality.Patches
Input validation and URL construction in the password recovery flow have been hardened.
Users should upgrade to v3.79.1 or later.
Workarounds
There are no complete workarounds. Upgrading to v3.79.1 is recommended.
References