{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cwe-863/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["payload-alt-text-plugin (\u003c 0.7.1)"],"_cs_severities":["high"],"_cs_tags":["authorization-bypass","cms-plugin","cwe-863"],"_cs_type":"threat","_cs_vendors":["jhb.software"],"content_html":"\u003cp\u003eThe @jhb.software/payload-alt-text-plugin version 0.7.0 contains an authorization bypass vulnerability affecting how it interacts with the Payload CMS Local API. When performing \u003ccode\u003efindByID\u003c/code\u003e and \u003ccode\u003eupdate\u003c/code\u003e operations, the plugin fails to explicitly set the \u003ccode\u003eoverrideAccess\u003c/code\u003e parameter to \u003ccode\u003efalse\u003c/code\u003e. By default, Payload's internal logic interprets the absence of this parameter as \u003ccode\u003etrue\u003c/code\u003e, effectively disabling collection-level access control checks.\u003c/p\u003e\n\u003cp\u003eThis flaw allows any authenticated user - regardless of their assigned role - to access or modify restricted upload collections. An attacker can read the content of protected upload documents and overwrite critical fields like \u003ccode\u003ealt\u003c/code\u003e and \u003ccode\u003ekeywords\u003c/code\u003e. The vulnerability is critical for environments that rely on Payload's access control features to manage document permissions. The impact is categorized as an Incorrect Authorization (CWE-863) issue.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker establishes a valid, low-privileged user session within the Payload CMS environment.\u003c/li\u003e\n\u003cli\u003eAttacker identifies a target upload collection that is meant to be restricted to administrative roles.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a POST request targeting the plugin's \u003ccode\u003e/api/alt-text-plugin/generate\u003c/code\u003e or \u003ccode\u003e/bulk\u003c/code\u003e endpoints.\u003c/li\u003e\n\u003cli\u003eAttacker includes specific JSON parameters (\u003ccode\u003eid\u003c/code\u003e, \u003ccode\u003ecollection\u003c/code\u003e, \u003ccode\u003elocale\u003c/code\u003e) to target a protected document.\u003c/li\u003e\n\u003cli\u003eThe plugin receives the request and executes a Payload Local API call without setting \u003ccode\u003eoverrideAccess: false\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003ePayload CMS internal logic defaults \u003ccode\u003eoverrideAccess\u003c/code\u003e to \u003ccode\u003etrue\u003c/code\u003e, bypassing all defined \u003ccode\u003eread\u003c/code\u003e or \u003ccode\u003eupdate\u003c/code\u003e access control functions for the collection.\u003c/li\u003e\n\u003cli\u003eThe plugin reads or modifies the protected \u003ccode\u003ealt\u003c/code\u003e and \u003ccode\u003ekeywords\u003c/code\u003e fields on behalf of the attacker.\u003c/li\u003e\n\u003cli\u003eAttacker successfully exfiltrates data or alters metadata in documents they are not authorized to access.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows unauthorized read/write access to sensitive metadata within restricted upload collections. An attacker can modify \u003ccode\u003ealt\u003c/code\u003e text and keywords for any document, potentially poisoning content, bypassing organizational access policies, or exfiltrating document metadata that should be restricted based on user role assignments.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the upgrade of \u003ccode\u003e@jhb.software/payload-alt-text-plugin\u003c/code\u003e to version 0.7.1 or later, where the \u003ccode\u003eoverrideAccess\u003c/code\u003e parameter is correctly set. For teams unable to patch immediately, implement a custom server-side guard to validate that the \u003ccode\u003ereq.user\u003c/code\u003e role has the necessary permissions for the target collection before the request reaches the plugin handler.\u003c/p\u003e\n","date_modified":"2026-09-11T00:54:16Z","date_published":"2026-09-11T00:54:16Z","id":"https://feed.craftedsignal.io/briefs/2026-09-payload-alt-text-auth-bypass/","summary":"The @jhb.software/payload-alt-text-plugin v0.7.0 fails to restrict Payload Local API calls, allowing authenticated users to bypass collection-level access controls to read and modify document data.","title":"Authorization Bypass in @jhb.software/payload-alt-text-plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-payload-alt-text-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cwe-863","version":"https://jsonfeed.org/version/1.1"}