HIGH 7.1 GitHub

CVE-2026-59965

@jhb.software/payload-alt-text-plugin: Alt Text Endpoint Authorization Bypass via Payload Local API `overrideAccess` Omission

## Alt Text Endpoint Authorization Bypass via Payload Local API `overrideAccess` Omission ### Summary `@jhb.software/payload-alt-text-plugin` v0.7.0 exposes custom Payload CMS endpoints (`POST /api/alt-text-plugin/generate` and `/bulk`) that call the Payload Local API (`findByID` and `update`) without setting `overrideAccess: false`. Because Payload's internal logic evaluates `shouldOverrideAccess = overrideAccess !== false`, omitting the parameter causes it to default to `true`, silently bypa

Affected Products

References

Published: 2026-09-10 · Source: GitHub · Feed updated: 2026-09-11
This high severity vulnerability with a CVSS score of 7.1 was published on 2026-09-10 via GitHub. Affected: npm/@jhb.software/payload-alt-text-plugin <= 0.7.0.
vulnfeed aggregates 13138 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.