PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-39397 delmaredigital CVE debrief

The @delmaredigital/payload-puck plugin for PayloadCMS, which integrates Puck visual page builder, had a critical vulnerability prior to version 0.6.23. This vulnerability, CVE-2026-39397, allowed unauthorized access to /api/puck/* CRUD endpoints, bypassing collection-level access control due to the default overrideAccess: true setting. The issue was fixed in version 0.6.23. Affected deployments should be reviewed for exposure and updated or mitigated.

Vendor
delmaredigital
Product
payload-puck
CVSS
CRITICAL 9.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-07
Original CVE updated
2026-07-24
Advisory published
2026-04-07
Advisory updated
2026-07-24

Who should care

Administrators and users of PayloadCMS with the @delmaredigital/payload-puck plugin installed should be aware of this vulnerability. Immediate action is recommended to ensure the plugin is updated to version 0.6.23 or later to prevent unauthorized access. Review of access controls and monitoring for /api/puck/* endpoints is also advised.

Technical summary

CVE-2026-39397 is a critical vulnerability in the @delmaredigital/payload-puck plugin for PayloadCMS. The plugin's /api/puck/* CRUD endpoints, registered by createPuckPlugin(), used the default overrideAccess: true setting, effectively bypassing all collection-level access control. This meant that any access options passed to createPuckPlugin() and any defined access rules on Puck-registered collections were ignored. The vulnerability was addressed in version 0.6.23 of the plugin. Defenders should focus on updating or mitigating affected deployments.

Defensive priority

Highest priority should be given to updating the @delmaredigital/payload-puck plugin to version 0.6.23 or later. Review and adjust access controls for PayloadCMS collections. Monitor for any unauthorized access attempts on /api/puck/* endpoints. Compensating controls should be considered for exposed systems while remediation is scheduled and verified. Asset inventory and vulnerability management teams should track exceptions and retest remediated assets. Change management windows should be planned for updates. Source tracking and logging should be reviewed for detection and response. Rollback plans should be in place if issues arise during updates. These actions should be taken with urgency due to the critical nature of the vulnerability and potential for exploitation. Security teams should coordinate with operators and platform teams to ensure coverage and verify evidence of mitigation. Monitoring and detection capabilities should be reviewed to ensure they can identify potential exploitation attempts. The vulnerability's high CVSS score of 9.4 indicates a high likelihood of exploitation and significant potential impact. Therefore, swift and thorough action is necessary to mitigate the risk effectively. The CVE and NVD provide additional context but may not have comprehensive details on affected systems or exploitation evidence. Local verification and defensive measures are crucial until updates can be applied. This situation requires immediate attention from security and IT teams to prevent potential breaches. The plugin's integration with Puck and PayloadCMS means that multiple stakeholders may need to be involved in remediation efforts. Communication and coordination will be key to ensuring timely and effective mitigation across the organization. Given the critical severity and potential for unauthorized access, this vulnerability should be treated as a high-priority incident until resolved. All relevant teams should be engaged in reviewing the current state of deployments, planning updates, and verifying the effectiveness of mitigations. The goal is to minimize exposure and prevent exploitation by swiftly applying the available fix and enhancing defensive措施

Recommended defensive actions

  • Update the @delmaredigital/payload-puck plugin to version 0.6.23 or later.
  • Review and adjust access controls for PayloadCMS collections.
  • Monitor for any unauthorized access attempts on /api/puck/* endpoints.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.

Evidence notes

The CVE record was published on 2026-04-07T21:17:18.160Z and last modified on 2026-07-24T21:10:00.143Z. The NVD entry is currently Analyzed. The vulnerability has a CVSS score of 9.4 and is classified as CRITICAL. Evidence is limited to CVE and NVD data. Defenders should verify payload-puck plugin version and access controls.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-07T21:17:18.160Z and has not been modified since then. The NVD entry is currently Analyzed.