CVE-2026-34746 describes an authenticated Server-Side Request Forgery (SSRF) vulnerability in Payload, a headless content management system, affecting versions prior to 3.79.1. This high-severity flaw (CVSS 7.7) allows authenticated users with upload permissions to compel the server to initiate HTTP requests to arbitrary URLs. The attack vector is network-based with low complexity and requires low privileges but no user interaction, potentially leading to high confidentiality impact by exposing internal network resources. Currently, there is no evidence of active exploitation, and public exploit code is not available, with only limited community discussion observed. Organizations using Payload should update to version 3.79.1 immediately to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.79.1CPE matchmatch criteria | cpe:2.3:a:payloadcms:payload:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.