OVERVIEW CVE-2026-39397 affects @delmaredigital/payload-puck, a PayloadCMS plugin that integrates the Puck visual page builder. Versions prior to 0.6.23 contain a critical access control vulnerability where all /api/puck/* CRUD endpoint handlers bypass collection-level access restrictions by defaulting to overrideAccess: true. This causes the plugin to ignore access options passed during initialization and disregard any access rules defined on Puck-registered collections. SEVERITY The vulnerability carries a CRITICAL CVSS 3.1 score of 9.8 (Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), indicating it is remotely exploitable over the network with low attack complexity and requires no authentication or user interaction. The attack grants attackers complete confidentiality, integrity, and availability impact, allowing unauthorized read, modification, or deletion of protected data through unauthenticated API access. EXPLOITATION STATUS The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities catalog and remains on the inactive Hot List, suggesting no active widespread exploitation has been publicly reported. The EPSS score of 0.00048 indicates minimal current exploitation probability, though this does not diminish the severe risk posed to unpatched instances. Organizations should immediately upgrade to version 0.6.23 or later to remediate this access control bypass.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.6.23CPE matchmatch criteria | cpe:2.3:a:delmaredigital:payload-puck:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.