Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-39397

36
FAUCET Score

OVERVIEW CVE-2026-39397 affects @delmaredigital/payload-puck, a PayloadCMS plugin that integrates the Puck visual page builder. Versions prior to 0.6.23 contain a critical access control vulnerability where all /api/puck/* CRUD endpoint handlers bypass collection-level access restrictions by defaulting to overrideAccess: true. This causes the plugin to ignore access options passed during initialization and disregard any access rules defined on Puck-registered collections. SEVERITY The vulnerability carries a CRITICAL CVSS 3.1 score of 9.8 (Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), indicating it is remotely exploitable over the network with low attack complexity and requires no authentication or user interaction. The attack grants attackers complete confidentiality, integrity, and availability impact, allowing unauthorized read, modification, or deletion of protected data through unauthenticated API access. EXPLOITATION STATUS The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities catalog and remains on the inactive Hot List, suggesting no active widespread exploitation has been publicly reported. The EPSS score of 0.00048 indicates minimal current exploitation probability, though this does not diminish the severe risk posed to unpatched instances. Organizations should immediately upgrade to version 0.6.23 or later to remediate this access control bypass.

Impacted Technologies

VendorProductVersion(s)CPE
< 0.6.23CPE matchmatch criteria
cpe:2.3:a:delmaredigital:payload-puck:*:*:*:*:*:node.js:*:*

CVSS Data

CVSS version used by this source: 3.1

9.4CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
LOW
Exploitability Score
3.9
Impact Score
5.5
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.38%
Probability of exploitation in next 30 days
EPSS Percentile
30.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0038 is in the 7th percentile among its peer group of 36,897 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

github_advisorypatch availablevia nvd_reference
View patch
npmpatch availablevia ghsa
Product: @delmaredigital/payload-puckFixed in: 0.6.23

Vendor Advisories (1)

npmGHSA-65w6-pf7x-5g85critical

@delmaredigital/payload-puc is missing authorization on /api/puck/* CRUD endpoints allows unauthenticated access to Puck-registered collections

Apr 8, 2026

References

github.com / delmaredigital/payload-puck/commit/9148201c6bbfa140d44546438027a2f8a70f79a4
Patch
github.com / delmaredigital/payload-puck/issues/7
ExploitIssue Tracking
github.com / delmaredigital/payload-puck/security/advisories/GHSA-65w6-pf7x-5g85
PatchVendor Advisory