CRITICAL
delmaredigital
CVE published 2026-04-07
CVE-2026-39397
The @delmaredigital/payload-puck plugin for PayloadCMS, which integrates Puck visual page builder, had a critical vulnerability prior to version 0.6.23. This vulnerability, CVE-2026-39397, allowed unauthorized access to /api/puck/* CRUD endpoints, bypassing collection-level access control due to the default overrideAccess: true setting. The issue was fixed in version 0.6.23. Affected deployments should be [truncated]