Search
Find a vulnerability
Search criteria
82 vulnerabilities found for payload by payloadcms
CVE-2026-106100 (GCVE-0-2026-106100)
Vulnerability from nvd – Published: 2026-10-06 16:56 – Updated: 2026-10-06 17:28
VLAI
EPSS
VEX
Title
Payload: Field-level write access bypass in Payload on MongoDB
Summary
Payload is a free and open source headless content management system. In @payloadcms/db-mongodb versions before 3.87.0 and canary versions before 4.0.0-canary.20, an authenticated user who can update a document can modify fields that field-level write access control does not permit that user to change. The Postgres and SQLite adapters are not affected. This issue is fixed in versions 3.87.0 and 4.0.0-canary.20.
Severity
7.1 (High)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-06 17:28 UTC
CWE
Assigner
References
4 references
| URL | Tags |
|---|---|
| https://github.com/payloadcms/payload/security/ad… | x_refsource_CONFIRM |
| https://github.com/payloadcms/payload/commit/2a69… | x_refsource_MISC |
| https://github.com/payloadcms/payload/commit/8f77… | x_refsource_MISC |
| https://github.com/payloadcms/payload/releases/ta… | x_refsource_MISC |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| payloadcms | payload |
Affected:
< 3.87.0
Affected: >= 4.0.0-canary.0, < 4.0.0-canary.20 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-106100",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-06T17:28:47.529744Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-06T17:28:55.961Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "payload",
"vendor": "payloadcms",
"versions": [
{
"status": "affected",
"version": "\u003c 3.87.0"
},
{
"status": "affected",
"version": "\u003e= 4.0.0-canary.0, \u003c 4.0.0-canary.20"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Payload is a free and open source headless content management system. In @payloadcms/db-mongodb versions before 3.87.0 and canary versions before 4.0.0-canary.20, an authenticated user who can update a document can modify fields that field-level write access control does not permit that user to change. The Postgres and SQLite adapters are not affected. This issue is fixed in versions 3.87.0 and 4.0.0-canary.20."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 7.1,
"baseSeverity": "HIGH",
"confidentialityImpact": "LOW",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-639",
"description": "CWE-639: Authorization Bypass Through User-Controlled Key",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-915",
"description": "CWE-915: Improperly Controlled Modification of Dynamically-Determined Object Attributes",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-06T16:56:55.715Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/payloadcms/payload/security/advisories/GHSA-4ww4-68q3-h7g5",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/payloadcms/payload/security/advisories/GHSA-4ww4-68q3-h7g5"
},
{
"name": "https://github.com/payloadcms/payload/commit/2a69863deb0e3c87e36c1b3b17ab2d5b02fcb941",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/payloadcms/payload/commit/2a69863deb0e3c87e36c1b3b17ab2d5b02fcb941"
},
{
"name": "https://github.com/payloadcms/payload/commit/8f77dffa9552885ec2710768cfee15b57e389935",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/payloadcms/payload/commit/8f77dffa9552885ec2710768cfee15b57e389935"
},
{
"name": "https://github.com/payloadcms/payload/releases/tag/v3.87.0",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/payloadcms/payload/releases/tag/v3.87.0"
}
],
"source": {
"advisory": "GHSA-4ww4-68q3-h7g5",
"discovery": "UNKNOWN"
},
"title": "Payload: Field-level write access bypass in Payload on MongoDB"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-106100",
"datePublished": "2026-10-06T16:56:55.715Z",
"dateReserved": "2026-10-06T15:33:55.332Z",
"dateUpdated": "2026-10-06T17:28:55.961Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-105868 (GCVE-0-2026-105868)
Vulnerability from nvd – Published: 2026-10-06 16:51 – Updated: 2026-10-09 01:17
VLAI
EPSS
VEX
Title
Payload: Uploaded XML files could execute same-origin JavaScript
Summary
Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, local upload configurations that accept XML files can store an XML file and stylesheet that execute JavaScript in the Payload origin when a logged-in user opens the file. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
Severity
SSVC
Exploitation: none
Automatable: yes
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-09 01:17 UTC
CWE
- CWE-434 - Unrestricted Upload of File with Dangerous Type
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://github.com/payloadcms/payload/security/ad… | x_refsource_CONFIRM |
| https://github.com/payloadcms/payload/commit/a8c3… | x_refsource_MISC |
| https://github.com/payloadcms/payload/releases/ta… | x_refsource_MISC |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| payloadcms | payload |
Affected:
< 3.90.0
Affected: >= 4.0.0-canary.0, < 4.0.0-canary.34 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-105868",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-09T01:17:27.846201Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-09T01:17:45.783Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "payload",
"vendor": "payloadcms",
"versions": [
{
"status": "affected",
"version": "\u003c 3.90.0"
},
{
"status": "affected",
"version": "\u003e= 4.0.0-canary.0, \u003c 4.0.0-canary.34"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, local upload configurations that accept XML files can store an XML file and stylesheet that execute JavaScript in the Payload origin when a logged-in user opens the file. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.6,
"baseSeverity": "HIGH",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "PASSIVE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-434",
"description": "CWE-434: Unrestricted Upload of File with Dangerous Type",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-06T16:51:34.054Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/payloadcms/payload/security/advisories/GHSA-9qpg-3cf8-w33x",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/payloadcms/payload/security/advisories/GHSA-9qpg-3cf8-w33x"
},
{
"name": "https://github.com/payloadcms/payload/commit/a8c3a8e8e2680c96ec4f66f5b3854c5df6c35adf",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/payloadcms/payload/commit/a8c3a8e8e2680c96ec4f66f5b3854c5df6c35adf"
},
{
"name": "https://github.com/payloadcms/payload/releases/tag/v3.90.0",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/payloadcms/payload/releases/tag/v3.90.0"
}
],
"source": {
"advisory": "GHSA-9qpg-3cf8-w33x",
"discovery": "UNKNOWN"
},
"title": "Payload: Uploaded XML files could execute same-origin JavaScript"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-105868",
"datePublished": "2026-10-06T16:51:34.054Z",
"dateReserved": "2026-10-05T23:06:29.748Z",
"dateUpdated": "2026-10-09T01:17:45.783Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-105867 (GCVE-0-2026-105867)
Vulnerability from nvd – Published: 2026-10-06 16:49 – Updated: 2026-10-06 17:24
VLAI
EPSS
VEX
Title
Payload: Client uploads could overwrite S3 objects
Summary
Payload is a free and open source headless content management system. In @payloadcms/storage-s3 versions before 3.90.0 and canary versions before 4.0.0-canary.34, an authenticated user can overwrite an existing S3 object belonging to another upload collection when client uploads are enabled for multiple collections sharing a bucket and useCompositePrefixes is false or unset. This bypasses the target collection's access controls and prior file validation. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-06 17:24 UTC
CWE
- CWE-639 - Authorization Bypass Through User-Controlled Key
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://github.com/payloadcms/payload/security/ad… | x_refsource_CONFIRM |
| https://github.com/payloadcms/payload/commit/2df8… | x_refsource_MISC |
| https://github.com/payloadcms/payload/releases/ta… | x_refsource_MISC |
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| payloadcms | payload |
Affected:
< 3.90.0
Affected: >= 4.0.0-canary.0, < 4.0.0-canary.34 |
|
| @payloadcms | storage-s3 |
Affected:
< 3.90.0
Affected: >= 4.0.0-canary.0, < 4.0.0-canary.34 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-105867",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-06T17:24:30.442506Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-06T17:24:39.913Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "payload",
"vendor": "payloadcms",
"versions": [
{
"status": "affected",
"version": "\u003c 3.90.0"
},
{
"status": "affected",
"version": "\u003e= 4.0.0-canary.0, \u003c 4.0.0-canary.34"
}
]
},
{
"product": "storage-s3",
"vendor": "@payloadcms",
"versions": [
{
"status": "affected",
"version": "\u003c 3.90.0"
},
{
"status": "affected",
"version": "\u003e= 4.0.0-canary.0, \u003c 4.0.0-canary.34"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Payload is a free and open source headless content management system. In @payloadcms/storage-s3 versions before 3.90.0 and canary versions before 4.0.0-canary.34, an authenticated user can overwrite an existing S3 object belonging to another upload collection when client uploads are enabled for multiple collections sharing a bucket and useCompositePrefixes is false or unset. This bypasses the target collection\u0027s access controls and prior file validation. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 7.1,
"baseSeverity": "HIGH",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "LOW",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "HIGH"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-639",
"description": "CWE-639: Authorization Bypass Through User-Controlled Key",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-06T16:49:12.532Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/payloadcms/payload/security/advisories/GHSA-7vg8-29qx-jgj8",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/payloadcms/payload/security/advisories/GHSA-7vg8-29qx-jgj8"
},
{
"name": "https://github.com/payloadcms/payload/commit/2df8238fbf17edfce335c399b90bf524ba9906a2",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/payloadcms/payload/commit/2df8238fbf17edfce335c399b90bf524ba9906a2"
},
{
"name": "https://github.com/payloadcms/payload/releases/tag/v3.90.0",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/payloadcms/payload/releases/tag/v3.90.0"
}
],
"source": {
"advisory": "GHSA-7vg8-29qx-jgj8",
"discovery": "UNKNOWN"
},
"title": "Payload: Client uploads could overwrite S3 objects"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-105867",
"datePublished": "2026-10-06T16:49:12.532Z",
"dateReserved": "2026-10-05T23:06:29.748Z",
"dateUpdated": "2026-10-06T17:24:39.913Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-105866 (GCVE-0-2026-105866)
Vulnerability from nvd – Published: 2026-10-06 16:46 – Updated: 2026-10-06 17:39
VLAI
EPSS
VEX
Title
Payload: Unauthenticated account-lockout denial of service
Summary
Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, an unauthenticated attacker who knows an account email address or username can abuse the account lockout mechanism of a local-authentication collection to prevent that account from signing in. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
Severity
SSVC
Exploitation: none
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-06 17:34 UTC
CWE
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://github.com/payloadcms/payload/security/ad… | x_refsource_CONFIRM |
| https://github.com/payloadcms/payload/commit/1c46… | x_refsource_MISC |
| https://github.com/payloadcms/payload/releases/ta… | x_refsource_MISC |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| payloadcms | payload |
Affected:
< 3.90.0
Affected: >= 4.0.0-canary.0, < 4.0.0-canary.34 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-105866",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-06T17:34:37.543263Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-06T17:39:09.686Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "payload",
"vendor": "payloadcms",
"versions": [
{
"status": "affected",
"version": "\u003c 3.90.0"
},
{
"status": "affected",
"version": "\u003e= 4.0.0-canary.0, \u003c 4.0.0-canary.34"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, an unauthenticated attacker who knows an account email address or username can abuse the account lockout mechanism of a local-authentication collection to prevent that account from signing in. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "LOW",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-307",
"description": "CWE-307: Improper Restriction of Excessive Authentication Attempts",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-645",
"description": "CWE-645: Overly Restrictive Account Lockout Mechanism",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-06T16:46:31.069Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/payloadcms/payload/security/advisories/GHSA-v5gf-vpjc-pc7w",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/payloadcms/payload/security/advisories/GHSA-v5gf-vpjc-pc7w"
},
{
"name": "https://github.com/payloadcms/payload/commit/1c46204a73a0a9f988a80c52690eee5a4ada3cf1",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/payloadcms/payload/commit/1c46204a73a0a9f988a80c52690eee5a4ada3cf1"
},
{
"name": "https://github.com/payloadcms/payload/releases/tag/v3.90.0",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/payloadcms/payload/releases/tag/v3.90.0"
}
],
"source": {
"advisory": "GHSA-v5gf-vpjc-pc7w",
"discovery": "UNKNOWN"
},
"title": "Payload: Unauthenticated account-lockout denial of service"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-105866",
"datePublished": "2026-10-06T16:46:31.069Z",
"dateReserved": "2026-10-05T23:06:29.748Z",
"dateUpdated": "2026-10-06T17:39:09.686Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-105865 (GCVE-0-2026-105865)
Vulnerability from nvd – Published: 2026-10-06 16:45 – Updated: 2026-10-06 17:11
VLAI
EPSS
VEX
Title
Payload: Incomplete validation during the upload file lifecycle
Summary
Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, an authenticated user who can update or delete uploads stored locally can cause file cleanup to remove unintended files outside the configured upload directory, resulting in data loss or service disruption. Deployments that restrict upload management to trusted users are less exposed. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
Severity
8.1 (High)
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-06 17:10 UTC
CWE
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://github.com/payloadcms/payload/security/ad… | x_refsource_CONFIRM |
| https://github.com/payloadcms/payload/commit/6b74… | x_refsource_MISC |
| https://github.com/payloadcms/payload/releases/ta… | x_refsource_MISC |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| payloadcms | payload |
Affected:
< 3.90.0
Affected: >= 4.0.0-canary.0, < 4.0.0-canary.34 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-105865",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-06T17:10:04.066384Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-06T17:11:18.423Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "payload",
"vendor": "payloadcms",
"versions": [
{
"status": "affected",
"version": "\u003c 3.90.0"
},
{
"status": "affected",
"version": "\u003e= 4.0.0-canary.0, \u003c 4.0.0-canary.34"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, an authenticated user who can update or delete uploads stored locally can cause file cleanup to remove unintended files outside the configured upload directory, resulting in data loss or service disruption. Deployments that restrict upload management to trusted users are less exposed. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.1,
"baseSeverity": "HIGH",
"confidentialityImpact": "NONE",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-22",
"description": "CWE-22: Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-73",
"description": "CWE-73: External Control of File Name or Path",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-06T16:45:09.932Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/payloadcms/payload/security/advisories/GHSA-p223-2wr2-j562",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/payloadcms/payload/security/advisories/GHSA-p223-2wr2-j562"
},
{
"name": "https://github.com/payloadcms/payload/commit/6b74418f628fa633c2f297e5919a9f91b383dc11",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/payloadcms/payload/commit/6b74418f628fa633c2f297e5919a9f91b383dc11"
},
{
"name": "https://github.com/payloadcms/payload/releases/tag/v3.90.0",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/payloadcms/payload/releases/tag/v3.90.0"
}
],
"source": {
"advisory": "GHSA-p223-2wr2-j562",
"discovery": "UNKNOWN"
},
"title": "Payload: Incomplete validation during the upload file lifecycle"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-105865",
"datePublished": "2026-10-06T16:45:09.932Z",
"dateReserved": "2026-10-05T23:06:29.748Z",
"dateUpdated": "2026-10-06T17:11:18.423Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-105864 (GCVE-0-2026-105864)
Vulnerability from nvd – Published: 2026-10-06 16:42 – Updated: 2026-10-06 17:25
VLAI
EPSS
VEX
Title
Payload: Cross-tenant create in @payloadcms/plugin-multi-tenant
Summary
Payload is a free and open source headless content management system. In @payloadcms/plugin-multi-tenant versions before 3.90.0 and canary versions before 4.0.0-canary.34, an authenticated user limited to one tenant can create a record in another tenant when at least one tenant-enabled collection exists. Reads and direct edits of existing documents in the target tenant are not bypassed. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-06 17:25 UTC
CWE
- CWE-863 - Incorrect Authorization
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://github.com/payloadcms/payload/security/ad… | x_refsource_CONFIRM |
| https://github.com/payloadcms/payload/commit/b8fc… | x_refsource_MISC |
| https://github.com/payloadcms/payload/releases/ta… | x_refsource_MISC |
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| payloadcms | payload |
Affected:
< 3.90.0
Affected: >= 4.0.0-canary.0, < 4.0.0-canary.34 |
|
| @payloadcms | plugin-multi-tenant |
Affected:
< 3.90.0
Affected: >= 4.0.0-canary.0, < 4.0.0-canary.34 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-105864",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-06T17:25:08.590502Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-06T17:25:18.758Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "payload",
"vendor": "payloadcms",
"versions": [
{
"status": "affected",
"version": "\u003c 3.90.0"
},
{
"status": "affected",
"version": "\u003e= 4.0.0-canary.0, \u003c 4.0.0-canary.34"
}
]
},
{
"product": "plugin-multi-tenant",
"vendor": "@payloadcms",
"versions": [
{
"status": "affected",
"version": "\u003c 3.90.0"
},
{
"status": "affected",
"version": "\u003e= 4.0.0-canary.0, \u003c 4.0.0-canary.34"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Payload is a free and open source headless content management system. In @payloadcms/plugin-multi-tenant versions before 3.90.0 and canary versions before 4.0.0-canary.34, an authenticated user limited to one tenant can create a record in another tenant when at least one tenant-enabled collection exists. Reads and direct edits of existing documents in the target tenant are not bypassed. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "LOW"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-863",
"description": "CWE-863: Incorrect Authorization",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-06T16:42:27.942Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/payloadcms/payload/security/advisories/GHSA-xhm9-gwgw-3q2q",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/payloadcms/payload/security/advisories/GHSA-xhm9-gwgw-3q2q"
},
{
"name": "https://github.com/payloadcms/payload/commit/b8fc06a18afb6974dc07f95ac1e541c716e5926b",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/payloadcms/payload/commit/b8fc06a18afb6974dc07f95ac1e541c716e5926b"
},
{
"name": "https://github.com/payloadcms/payload/releases/tag/v3.90.0",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/payloadcms/payload/releases/tag/v3.90.0"
}
],
"source": {
"advisory": "GHSA-xhm9-gwgw-3q2q",
"discovery": "UNKNOWN"
},
"title": "Payload: Cross-tenant create in @payloadcms/plugin-multi-tenant"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-105864",
"datePublished": "2026-10-06T16:42:27.942Z",
"dateReserved": "2026-10-05T23:06:29.748Z",
"dateUpdated": "2026-10-06T17:25:18.758Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-105863 (GCVE-0-2026-105863)
Vulnerability from nvd – Published: 2026-10-06 16:39 – Updated: 2026-10-09 01:15
VLAI
EPSS
VEX
Title
Payload authentication token field handling issue
Summary
Payload is a free and open source headless content management system. In versions after 3.0.0 and before 3.90.0, a custom field option that maps a field to a reserved authentication claim name can place unintended values in the authentication token issued at login. This issue is fixed in version 3.90.0.
Severity
SSVC
Exploitation: none
Automatable: yes
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-09 01:15 UTC
CWE
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://github.com/payloadcms/payload/security/ad… | x_refsource_CONFIRM |
| https://github.com/payloadcms/payload/commit/56cd… | x_refsource_MISC |
| https://github.com/payloadcms/payload/releases/ta… | x_refsource_MISC |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| payloadcms | payload |
Affected:
>= 3.0.0, < 3.90.0
Affected: >= 4.0.0-canary.0, < 4.0.0-canary.34 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-105863",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-09T01:15:22.805238Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-09T01:15:33.512Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "payload",
"vendor": "payloadcms",
"versions": [
{
"status": "affected",
"version": "\u003e= 3.0.0, \u003c 3.90.0"
},
{
"status": "affected",
"version": "\u003e= 4.0.0-canary.0, \u003c 4.0.0-canary.34"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Payload is a free and open source headless content management system. In versions after 3.0.0 and before 3.90.0, a custom field option that maps a field to a reserved authentication claim name can place unintended values in the authentication token issued at login. This issue is fixed in version 3.90.0."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 9.2,
"baseSeverity": "CRITICAL",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-290",
"description": "CWE-290: Authentication Bypass by Spoofing",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-915",
"description": "CWE-915: Improperly Controlled Modification of Dynamically-Determined Object Attributes",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-06T16:39:44.912Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/payloadcms/payload/security/advisories/GHSA-66wr-7vmr-p5jq",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/payloadcms/payload/security/advisories/GHSA-66wr-7vmr-p5jq"
},
{
"name": "https://github.com/payloadcms/payload/commit/56cd5cd050a57daebf33159e41e5ff9d4a45239c",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/payloadcms/payload/commit/56cd5cd050a57daebf33159e41e5ff9d4a45239c"
},
{
"name": "https://github.com/payloadcms/payload/releases/tag/v3.90.0",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/payloadcms/payload/releases/tag/v3.90.0"
}
],
"source": {
"advisory": "GHSA-66wr-7vmr-p5jq",
"discovery": "UNKNOWN"
},
"title": "Payload authentication token field handling issue"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-105863",
"datePublished": "2026-10-06T16:39:44.912Z",
"dateReserved": "2026-10-05T23:06:29.748Z",
"dateUpdated": "2026-10-09T01:15:33.512Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-105862 (GCVE-0-2026-105862)
Vulnerability from nvd – Published: 2026-10-06 16:37 – Updated: 2026-10-06 17:24
VLAI
EPSS
VEX
Title
Payload: Bypassed sanitization of user uploaded SVGs
Summary
Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, a collection that allows downloadable SVG uploads can store a malicious SVG that bypasses sanitization and executes attacker-controlled JavaScript when a user downloads and opens the SVG. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
Severity
8.7 (High)
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-06 17:23 UTC
CWE
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://github.com/payloadcms/payload/security/ad… | x_refsource_CONFIRM |
| https://github.com/payloadcms/payload/commit/a8c3… | x_refsource_MISC |
| https://github.com/payloadcms/payload/releases/ta… | x_refsource_MISC |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| payloadcms | payload |
Affected:
< 3.90.0
Affected: >= 4.0.0-canary.0, < 4.0.0-canary.34 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-105862",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-06T17:23:55.762440Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-06T17:24:09.513Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "payload",
"vendor": "payloadcms",
"versions": [
{
"status": "affected",
"version": "\u003c 3.90.0"
},
{
"status": "affected",
"version": "\u003e= 4.0.0-canary.0, \u003c 4.0.0-canary.34"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, a collection that allows downloadable SVG uploads can store a malicious SVG that bypasses sanitization and executes attacker-controlled JavaScript when a user downloads and opens the SVG. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 8.7,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "CHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "CWE-79: Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-434",
"description": "CWE-434: Unrestricted Upload of File with Dangerous Type",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-06T16:37:59.487Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/payloadcms/payload/security/advisories/GHSA-2pwp-2369-8fg3",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/payloadcms/payload/security/advisories/GHSA-2pwp-2369-8fg3"
},
{
"name": "https://github.com/payloadcms/payload/commit/a8c3a8e8e2680c96ec4f66f5b3854c5df6c35adf",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/payloadcms/payload/commit/a8c3a8e8e2680c96ec4f66f5b3854c5df6c35adf"
},
{
"name": "https://github.com/payloadcms/payload/releases/tag/v3.90.0",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/payloadcms/payload/releases/tag/v3.90.0"
}
],
"source": {
"advisory": "GHSA-2pwp-2369-8fg3",
"discovery": "UNKNOWN"
},
"title": "Payload: Bypassed sanitization of user uploaded SVGs"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-105862",
"datePublished": "2026-10-06T16:37:59.487Z",
"dateReserved": "2026-10-05T23:06:29.748Z",
"dateUpdated": "2026-10-06T17:24:09.513Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-105861 (GCVE-0-2026-105861)
Vulnerability from nvd – Published: 2026-10-06 16:34 – Updated: 2026-10-06 17:39
VLAI
EPSS
VEX
Title
Payload external upload trust validation issue
Summary
Payload is a free and open source headless content management system. In versions after 3.0.0 and before 3.90.0, authenticated external URL-based upload retrieval can forward authentication data to a redirected destination that was not verified as trusted, potentially exposing a valid session to an unintended recipient. This issue is fixed in version 3.90.0.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-06 17:34 UTC
CWE
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://github.com/payloadcms/payload/security/ad… | x_refsource_CONFIRM |
| https://github.com/payloadcms/payload/commit/ba5c… | x_refsource_MISC |
| https://github.com/payloadcms/payload/releases/ta… | x_refsource_MISC |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| payloadcms | payload |
Affected:
> 3.0.0, < 3.90.0
Affected: > 4.0.0-canary.0, < 4.0.0-canary-34 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-105861",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-06T17:34:13.957850Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-06T17:39:16.866Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "payload",
"vendor": "payloadcms",
"versions": [
{
"status": "affected",
"version": "\u003e 3.0.0, \u003c 3.90.0"
},
{
"status": "affected",
"version": "\u003e 4.0.0-canary.0, \u003c 4.0.0-canary-34"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Payload is a free and open source headless content management system. In versions after 3.0.0 and before 3.90.0, authenticated external URL-based upload retrieval can forward authentication data to a redirected destination that was not verified as trusted, potentially exposing a valid session to an unintended recipient. This issue is fixed in version 3.90.0."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 7.2,
"baseSeverity": "HIGH",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "ACTIVE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-200",
"description": "CWE-200: Exposure of Sensitive Information to an Unauthorized Actor",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-346",
"description": "CWE-346: Origin Validation Error",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-06T16:34:41.622Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/payloadcms/payload/security/advisories/GHSA-pj5h-5q6c-3pfx",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/payloadcms/payload/security/advisories/GHSA-pj5h-5q6c-3pfx"
},
{
"name": "https://github.com/payloadcms/payload/commit/ba5cf6ae20d27a2c15106cb37466419031f86e6d",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/payloadcms/payload/commit/ba5cf6ae20d27a2c15106cb37466419031f86e6d"
},
{
"name": "https://github.com/payloadcms/payload/releases/tag/v3.90.0",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/payloadcms/payload/releases/tag/v3.90.0"
}
],
"source": {
"advisory": "GHSA-pj5h-5q6c-3pfx",
"discovery": "UNKNOWN"
},
"title": "Payload external upload trust validation issue"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-105861",
"datePublished": "2026-10-06T16:34:41.622Z",
"dateReserved": "2026-10-05T23:06:29.748Z",
"dateUpdated": "2026-10-06T17:39:16.866Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-105860 (GCVE-0-2026-105860)
Vulnerability from nvd – Published: 2026-10-06 16:33 – Updated: 2026-10-06 17:15
VLAI
EPSS
VEX
Title
Payload: Tenant authorization bypass in Multi-Tenant Plugin
Summary
Payload is a free and open source headless content management system. In @payloadcms/plugin-multi-tenant versions before 3.90.0 and canary versions before 4.0.0-canary.34, the default tenant array field access allows an authenticated user to assign the user's own account to other tenants. Deployments that replace the default behavior with secured tenants arrayFieldAccess.create and tenants arrayFieldAccess.update functions are not affected by this behavior. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-06 17:14 UTC
CWE
- CWE-862 - Missing Authorization
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://github.com/payloadcms/payload/security/ad… | x_refsource_CONFIRM |
| https://github.com/payloadcms/payload/commit/19b5… | x_refsource_MISC |
| https://github.com/payloadcms/payload/releases/ta… | x_refsource_MISC |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| payloadcms | payload |
Affected:
< 3.90.0
Affected: >= 4.0.0-canary.0, < 4.0.0-canary.34 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-105860",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-06T17:14:06.093190Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-06T17:15:03.137Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "payload",
"vendor": "payloadcms",
"versions": [
{
"status": "affected",
"version": "\u003c 3.90.0"
},
{
"status": "affected",
"version": "\u003e= 4.0.0-canary.0, \u003c 4.0.0-canary.34"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Payload is a free and open source headless content management system. In @payloadcms/plugin-multi-tenant versions before 3.90.0 and canary versions before 4.0.0-canary.34, the default tenant array field access allows an authenticated user to assign the user\u0027s own account to other tenants. Deployments that replace the default behavior with secured tenants arrayFieldAccess.create and tenants arrayFieldAccess.update functions are not affected by this behavior. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 7.1,
"baseSeverity": "HIGH",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "HIGH"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-862",
"description": "CWE-862: Missing Authorization",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-06T16:33:20.213Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/payloadcms/payload/security/advisories/GHSA-p96c-xwx8-3cqj",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/payloadcms/payload/security/advisories/GHSA-p96c-xwx8-3cqj"
},
{
"name": "https://github.com/payloadcms/payload/commit/19b58692d20d3947f31124bf7a88ac14a5ebf02e",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/payloadcms/payload/commit/19b58692d20d3947f31124bf7a88ac14a5ebf02e"
},
{
"name": "https://github.com/payloadcms/payload/releases/tag/v3.90.0",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/payloadcms/payload/releases/tag/v3.90.0"
}
],
"source": {
"advisory": "GHSA-p96c-xwx8-3cqj",
"discovery": "UNKNOWN"
},
"title": "Payload: Tenant authorization bypass in Multi-Tenant Plugin"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-105860",
"datePublished": "2026-10-06T16:33:20.213Z",
"dateReserved": "2026-10-05T23:06:29.748Z",
"dateUpdated": "2026-10-06T17:15:03.137Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-105859 (GCVE-0-2026-105859)
Vulnerability from nvd – Published: 2026-10-06 16:31 – Updated: 2026-10-06 17:37
VLAI
EPSS
VEX
Title
Payload: Unauthorized update to collection documents
Summary
Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, an attacker can submit a request to a specific update endpoint that modifies collection documents without enforcing collection or field-level access control when orderable is enabled on a collection or join field. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
Severity
9.8 (Critical)
SSVC
Exploitation: none
Automatable: yes
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-06 17:37 UTC
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://github.com/payloadcms/payload/security/ad… | x_refsource_CONFIRM |
| https://github.com/payloadcms/payload/commit/36fa… | x_refsource_MISC |
| https://github.com/payloadcms/payload/releases/ta… | x_refsource_MISC |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| payloadcms | payload |
Affected:
< 3.90.0
Affected: >= 4.0.0-canary.0, < 4.0.0-canary.34 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-105859",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-06T17:37:15.906390Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-06T17:37:22.423Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "payload",
"vendor": "payloadcms",
"versions": [
{
"status": "affected",
"version": "\u003c 3.90.0"
},
{
"status": "affected",
"version": "\u003e= 4.0.0-canary.0, \u003c 4.0.0-canary.34"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, an attacker can submit a request to a specific update endpoint that modifies collection documents without enforcing collection or field-level access control when orderable is enabled on a collection or join field. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-639",
"description": "CWE-639: Authorization Bypass Through User-Controlled Key",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-862",
"description": "CWE-862: Missing Authorization",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-06T16:31:52.275Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/payloadcms/payload/security/advisories/GHSA-f7hx-52q9-hcrf",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/payloadcms/payload/security/advisories/GHSA-f7hx-52q9-hcrf"
},
{
"name": "https://github.com/payloadcms/payload/commit/36fa9af73dd04fa59f4b4a06d11454538c4c1409",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/payloadcms/payload/commit/36fa9af73dd04fa59f4b4a06d11454538c4c1409"
},
{
"name": "https://github.com/payloadcms/payload/releases/tag/v3.90.0",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/payloadcms/payload/releases/tag/v3.90.0"
}
],
"source": {
"advisory": "GHSA-f7hx-52q9-hcrf",
"discovery": "UNKNOWN"
},
"title": "Payload: Unauthorized update to collection documents"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-105859",
"datePublished": "2026-10-06T16:31:52.275Z",
"dateReserved": "2026-10-05T23:06:29.748Z",
"dateUpdated": "2026-10-06T17:37:22.423Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-105858 (GCVE-0-2026-105858)
Vulnerability from nvd – Published: 2026-10-06 16:29 – Updated: 2026-10-09 01:14
VLAI
EPSS
VEX
Title
Payload: Remote Code Execution through first-register
Summary
Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, a crafted request to the public first-register operation can execute code remotely when local authentication is enabled and no initial user has been created. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
Severity
8.1 (High)
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-09 01:13 UTC
CWE
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://github.com/payloadcms/payload/security/ad… | x_refsource_CONFIRM |
| https://github.com/payloadcms/payload/commit/e947… | x_refsource_MISC |
| https://github.com/payloadcms/payload/releases/ta… | x_refsource_MISC |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| payloadcms | payload |
Affected:
< 3.90.0
Affected: >= 4.0.0-canary.0, < 4.0.0-canary.34 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-105858",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-09T01:13:53.118550Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-09T01:14:15.431Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "payload",
"vendor": "payloadcms",
"versions": [
{
"status": "affected",
"version": "\u003c 3.90.0"
},
{
"status": "affected",
"version": "\u003e= 4.0.0-canary.0, \u003c 4.0.0-canary.34"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, a crafted request to the public first-register operation can execute code remotely when local authentication is enabled and no initial user has been created. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.1,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-94",
"description": "CWE-94: Improper Control of Generation of Code (\u0027Code Injection\u0027)",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-1321",
"description": "CWE-1321: Improperly Controlled Modification of Object Prototype Attributes (\u0027Prototype Pollution\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-06T16:29:52.420Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/payloadcms/payload/security/advisories/GHSA-97rh-rhh2-7vjv",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/payloadcms/payload/security/advisories/GHSA-97rh-rhh2-7vjv"
},
{
"name": "https://github.com/payloadcms/payload/commit/e947fc4ba4a434f276d043386e501b1d14eda679",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/payloadcms/payload/commit/e947fc4ba4a434f276d043386e501b1d14eda679"
},
{
"name": "https://github.com/payloadcms/payload/releases/tag/v3.90.0",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/payloadcms/payload/releases/tag/v3.90.0"
}
],
"source": {
"advisory": "GHSA-97rh-rhh2-7vjv",
"discovery": "UNKNOWN"
},
"title": "Payload: Remote Code Execution through first-register"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-105858",
"datePublished": "2026-10-06T16:29:52.420Z",
"dateReserved": "2026-10-05T23:06:29.748Z",
"dateUpdated": "2026-10-09T01:14:15.431Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-105857 (GCVE-0-2026-105857)
Vulnerability from nvd – Published: 2026-10-06 16:26 – Updated: 2026-10-06 17:23
VLAI
EPSS
VEX
Title
Payload: RCE in Payload Form Builder
Summary
Payload is a free and open source headless content management system. In @payloadcms/plugin-form-builder versions before 3.90.0 and canary versions before 4.0.0-canary.34, an attacker can craft a form submission that executes code remotely on the server. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
Severity
10 (Critical)
SSVC
Exploitation: none
Automatable: yes
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-06 17:23 UTC
CWE
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://github.com/payloadcms/payload/security/ad… | x_refsource_CONFIRM |
| https://github.com/payloadcms/payload/commit/333b… | x_refsource_MISC |
| https://github.com/payloadcms/payload/releases/ta… | x_refsource_MISC |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| payloadcms | payload |
Affected:
< 3.90.0
Affected: >= 4.0.0-canary.0, < 4.0.0-canary.34 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-105857",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-06T17:23:21.462360Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-06T17:23:32.964Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "payload",
"vendor": "payloadcms",
"versions": [
{
"status": "affected",
"version": "\u003c 3.90.0"
},
{
"status": "affected",
"version": "\u003e= 4.0.0-canary.0, \u003c 4.0.0-canary.34"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Payload is a free and open source headless content management system. In @payloadcms/plugin-form-builder versions before 3.90.0 and canary versions before 4.0.0-canary.34, an attacker can craft a form submission that executes code remotely on the server. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 10,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "CHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-94",
"description": "CWE-94: Improper Control of Generation of Code (\u0027Code Injection\u0027)",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-1321",
"description": "CWE-1321: Improperly Controlled Modification of Object Prototype Attributes (\u0027Prototype Pollution\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-06T16:26:54.885Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/payloadcms/payload/security/advisories/GHSA-r488-j9vj-wx3q",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/payloadcms/payload/security/advisories/GHSA-r488-j9vj-wx3q"
},
{
"name": "https://github.com/payloadcms/payload/commit/333b82b9f3e685fed6826c2e3270da79df8336c6",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/payloadcms/payload/commit/333b82b9f3e685fed6826c2e3270da79df8336c6"
},
{
"name": "https://github.com/payloadcms/payload/releases/tag/v3.90.0",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/payloadcms/payload/releases/tag/v3.90.0"
}
],
"source": {
"advisory": "GHSA-r488-j9vj-wx3q",
"discovery": "UNKNOWN"
},
"title": "Payload: RCE in Payload Form Builder"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-105857",
"datePublished": "2026-10-06T16:26:54.885Z",
"dateReserved": "2026-10-05T23:06:29.748Z",
"dateUpdated": "2026-10-06T17:23:32.964Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-105856 (GCVE-0-2026-105856)
Vulnerability from nvd – Published: 2026-10-06 16:23 – Updated: 2026-10-06 17:39
VLAI
EPSS
VEX
Title
Payload: SQL injection in SQLite/Postgres
Summary
Payload is a free and open source headless content management system. Prior to 3.90.0 and 4.0.0-canary.34, an attacker with read and create or update access to a collection containing a json field or a blocks field with blocksAsJSON enabled can inject SQL through a crafted field path and operators. Collections without those fields are not affected, and richText fields are not affected. The SQLite packages are fixed in versions 3.90.0 and 4.0.0-canary.34, and the Postgres packages are fixed in version 3.73.0.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-06 17:34 UTC
CWE
- CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://github.com/payloadcms/payload/security/ad… | x_refsource_CONFIRM |
| https://github.com/payloadcms/payload/commit/03b7… | x_refsource_MISC |
| https://github.com/payloadcms/payload/releases/ta… | x_refsource_MISC |
Impacted products
5 products
| Vendor | Product | Version | |
|---|---|---|---|
| payloadcms | payload |
Affected:
>= 3.0.0, < 3.90.0
Affected: >= 4.0.0-canary.0, < 4.0.0-canary.34 |
|
| @payloadcms | db-d1-sqlite |
Affected:
>= 3.0.0, < 3.90.0
Affected: >= 4.0.0-canary.0, < 4.0.0-canary.34 |
|
| @payloadcms | db-postgres |
Affected:
>= 3.0.0 < 3.73.0
|
|
| @payloadcms | db-sqlite |
Affected:
>= 3.0.0, < 3.90.0
Affected: >= 4.0.0-canary.0, < 4.0.0-canary.34 |
|
| @payloadcms | db-vercel-postgres |
Affected:
>= 3.0.0 < 3.73.0
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-105856",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-06T17:34:12.712056Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-06T17:39:22.911Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "payload",
"vendor": "payloadcms",
"versions": [
{
"status": "affected",
"version": "\u003e= 3.0.0, \u003c 3.90.0"
},
{
"status": "affected",
"version": "\u003e= 4.0.0-canary.0, \u003c 4.0.0-canary.34"
}
]
},
{
"product": "db-d1-sqlite",
"vendor": "@payloadcms",
"versions": [
{
"status": "affected",
"version": "\u003e= 3.0.0, \u003c 3.90.0"
},
{
"status": "affected",
"version": "\u003e= 4.0.0-canary.0, \u003c 4.0.0-canary.34"
}
]
},
{
"product": "db-postgres",
"vendor": "@payloadcms",
"versions": [
{
"status": "affected",
"version": "\u003e= 3.0.0 \u003c 3.73.0"
}
]
},
{
"product": "db-sqlite",
"vendor": "@payloadcms",
"versions": [
{
"status": "affected",
"version": "\u003e= 3.0.0, \u003c 3.90.0"
},
{
"status": "affected",
"version": "\u003e= 4.0.0-canary.0, \u003c 4.0.0-canary.34"
}
]
},
{
"product": "db-vercel-postgres",
"vendor": "@payloadcms",
"versions": [
{
"status": "affected",
"version": "\u003e= 3.0.0 \u003c 3.73.0"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Payload is a free and open source headless content management system. Prior to 3.90.0 and 4.0.0-canary.34, an attacker with read and create or update access to a collection containing a json field or a blocks field with blocksAsJSON enabled can inject SQL through a crafted field path and operators. Collections without those fields are not affected, and richText fields are not affected. The SQLite packages are fixed in versions 3.90.0 and 4.0.0-canary.34, and the Postgres packages are fixed in version 3.73.0."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.6,
"baseSeverity": "HIGH",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-89",
"description": "CWE-89: Improper Neutralization of Special Elements used in an SQL Command (\u0027SQL Injection\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-06T16:23:58.643Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/payloadcms/payload/security/advisories/GHSA-pj7x-6wpf-pgvp",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/payloadcms/payload/security/advisories/GHSA-pj7x-6wpf-pgvp"
},
{
"name": "https://github.com/payloadcms/payload/commit/03b78c7e0901d19c67f07bdf6396a276010adbcc",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/payloadcms/payload/commit/03b78c7e0901d19c67f07bdf6396a276010adbcc"
},
{
"name": "https://github.com/payloadcms/payload/releases/tag/v3.90.0",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/payloadcms/payload/releases/tag/v3.90.0"
}
],
"source": {
"advisory": "GHSA-pj7x-6wpf-pgvp",
"discovery": "UNKNOWN"
},
"title": "Payload: SQL injection in SQLite/Postgres"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-105856",
"datePublished": "2026-10-06T16:23:58.643Z",
"dateReserved": "2026-10-05T23:06:29.748Z",
"dateUpdated": "2026-10-06T17:39:22.911Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-105855 (GCVE-0-2026-105855)
Vulnerability from nvd – Published: 2026-10-06 16:18 – Updated: 2026-10-06 17:18
VLAI
EPSS
VEX
Title
Payload: Field-level password update restrictions were not enforced
Summary
Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, the server fails to enforce a field-level access.update restriction on the password field of an authentication collection. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-06 17:18 UTC
CWE
- CWE-284 - Improper Access Control
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://github.com/payloadcms/payload/security/ad… | x_refsource_CONFIRM |
| https://github.com/payloadcms/payload/commit/9de9… | x_refsource_MISC |
| https://github.com/payloadcms/payload/releases/ta… | x_refsource_MISC |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| payloadcms | payload |
Affected:
< 3.90.0
Affected: >= 4.0.0-canary.0, < 4.0.0-canary.34 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-105855",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-06T17:18:36.218370Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-06T17:18:56.091Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "payload",
"vendor": "payloadcms",
"versions": [
{
"status": "affected",
"version": "\u003c 3.90.0"
},
{
"status": "affected",
"version": "\u003e= 4.0.0-canary.0, \u003c 4.0.0-canary.34"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, the server fails to enforce a field-level access.update restriction on the password field of an authentication collection. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 7.6,
"baseSeverity": "HIGH",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-284",
"description": "CWE-284: Improper Access Control",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-06T16:18:53.672Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/payloadcms/payload/security/advisories/GHSA-fx49-4h83-wjv9",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/payloadcms/payload/security/advisories/GHSA-fx49-4h83-wjv9"
},
{
"name": "https://github.com/payloadcms/payload/commit/9de9e7911e29d60870a1d5480412524c63d6411e",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/payloadcms/payload/commit/9de9e7911e29d60870a1d5480412524c63d6411e"
},
{
"name": "https://github.com/payloadcms/payload/releases/tag/v3.90.0",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/payloadcms/payload/releases/tag/v3.90.0"
}
],
"source": {
"advisory": "GHSA-fx49-4h83-wjv9",
"discovery": "UNKNOWN"
},
"title": "Payload: Field-level password update restrictions were not enforced"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-105855",
"datePublished": "2026-10-06T16:18:53.672Z",
"dateReserved": "2026-10-05T23:06:29.748Z",
"dateUpdated": "2026-10-06T17:18:56.091Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-105854 (GCVE-0-2026-105854)
Vulnerability from nvd – Published: 2026-10-06 16:17 – Updated: 2026-10-06 17:30
VLAI
EPSS
VEX
Title
Payload: ReDoS in Multipart Content-Type Validation
Summary
Payload is a free and open source headless content management system. In versions from 3.0.0 before 3.90.0 and canary versions before 4.0.0-canary.34, a malformed multipart request body can cause multipart Content-Type processing to take an extremely long time, resulting in uncontrolled resource consumption. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
Severity
SSVC
Exploitation: none
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-06 17:29 UTC
CWE
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://github.com/payloadcms/payload/security/ad… | x_refsource_CONFIRM |
| https://github.com/payloadcms/payload/commit/0084… | x_refsource_MISC |
| https://github.com/payloadcms/payload/releases/ta… | x_refsource_MISC |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| payloadcms | payload |
Affected:
>= 3.0.0, < 3.90.0
Affected: >= 4.0.0-canary.0, < 4.0.0-canary.34 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-105854",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-06T17:29:52.942510Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-06T17:30:01.567Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "payload",
"vendor": "payloadcms",
"versions": [
{
"status": "affected",
"version": "\u003e= 3.0.0, \u003c 3.90.0"
},
{
"status": "affected",
"version": "\u003e= 4.0.0-canary.0, \u003c 4.0.0-canary.34"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Payload is a free and open source headless content management system. In versions from 3.0.0 before 3.90.0 and canary versions before 4.0.0-canary.34, a malformed multipart request body can cause multipart Content-Type processing to take an extremely long time, resulting in uncontrolled resource consumption. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.7,
"baseSeverity": "HIGH",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-400",
"description": "CWE-400: Uncontrolled Resource Consumption",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-1333",
"description": "CWE-1333: Inefficient Regular Expression Complexity",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-06T16:17:30.893Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/payloadcms/payload/security/advisories/GHSA-2g7p-5934-q4w7",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/payloadcms/payload/security/advisories/GHSA-2g7p-5934-q4w7"
},
{
"name": "https://github.com/payloadcms/payload/commit/0084bd51fb7742b26a88431bb84cb1696857e6dc",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/payloadcms/payload/commit/0084bd51fb7742b26a88431bb84cb1696857e6dc"
},
{
"name": "https://github.com/payloadcms/payload/releases/tag/v3.90.0",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/payloadcms/payload/releases/tag/v3.90.0"
}
],
"source": {
"advisory": "GHSA-2g7p-5934-q4w7",
"discovery": "UNKNOWN"
},
"title": "Payload: ReDoS in Multipart Content-Type Validation"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-105854",
"datePublished": "2026-10-06T16:17:30.893Z",
"dateReserved": "2026-10-05T23:06:29.748Z",
"dateUpdated": "2026-10-06T17:30:01.567Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-105853 (GCVE-0-2026-105853)
Vulnerability from nvd – Published: 2026-10-06 16:16 – Updated: 2026-10-09 01:12
VLAI
EPSS
VEX
Title
Payload: Token refresh and password reset responses may expose restricted user fields
Summary
Payload is a free and open source headless content management system. In versions from 3.0.0 before 3.90.0 and canary versions before 4.0.0-canary.34, token refresh responses and password reset responses can independently return hidden or read-restricted fields that the requesting user cannot access. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
Severity
SSVC
Exploitation: none
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-09 01:12 UTC
CWE
- CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://github.com/payloadcms/payload/security/ad… | x_refsource_CONFIRM |
| https://github.com/payloadcms/payload/commit/f5f1… | x_refsource_MISC |
| https://github.com/payloadcms/payload/releases/ta… | x_refsource_MISC |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| payloadcms | payload |
Affected:
>= 3.0.0, < 3.90.0
Affected: >= 4.0.0-canary.0, < 4.0.0-canary.34 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-105853",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-09T01:12:33.886805Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-09T01:12:54.335Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "payload",
"vendor": "payloadcms",
"versions": [
{
"status": "affected",
"version": "\u003e= 3.0.0, \u003c 3.90.0"
},
{
"status": "affected",
"version": "\u003e= 4.0.0-canary.0, \u003c 4.0.0-canary.34"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Payload is a free and open source headless content management system. In versions from 3.0.0 before 3.90.0 and canary versions before 4.0.0-canary.34, token refresh responses and password reset responses can independently return hidden or read-restricted fields that the requesting user cannot access. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 7.1,
"baseSeverity": "HIGH",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "NONE"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-200",
"description": "CWE-200: Exposure of Sensitive Information to an Unauthorized Actor",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-06T16:16:14.512Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/payloadcms/payload/security/advisories/GHSA-xgv3-crq2-6f69",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/payloadcms/payload/security/advisories/GHSA-xgv3-crq2-6f69"
},
{
"name": "https://github.com/payloadcms/payload/commit/f5f1283d275c58b30e2faa6be7cdc4d49451ea91",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/payloadcms/payload/commit/f5f1283d275c58b30e2faa6be7cdc4d49451ea91"
},
{
"name": "https://github.com/payloadcms/payload/releases/tag/v3.90.0",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/payloadcms/payload/releases/tag/v3.90.0"
}
],
"source": {
"advisory": "GHSA-xgv3-crq2-6f69",
"discovery": "UNKNOWN"
},
"title": "Payload: Token refresh and password reset responses may expose restricted user fields"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-105853",
"datePublished": "2026-10-06T16:16:14.512Z",
"dateReserved": "2026-10-05T23:06:29.748Z",
"dateUpdated": "2026-10-09T01:12:54.335Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-105852 (GCVE-0-2026-105852)
Vulnerability from nvd – Published: 2026-10-06 16:15 – Updated: 2026-10-06 17:22
VLAI
EPSS
VEX
Title
Payload relationship-query authorization bypass
Summary
Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, querying a readable collection with a relationship to another collection can expose information about related documents protected by access.read where constraints. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
Severity
SSVC
Exploitation: none
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-06 17:22 UTC
CWE
- CWE-862 - Missing Authorization
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://github.com/payloadcms/payload/security/ad… | x_refsource_CONFIRM |
| https://github.com/payloadcms/payload/commit/9405… | x_refsource_MISC |
| https://github.com/payloadcms/payload/releases/ta… | x_refsource_MISC |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| payloadcms | payload |
Affected:
< 3.90.0
Affected: >= 4.0.0-canary.0, < 4.0.0-canary.34 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-105852",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-06T17:22:37.286471Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-06T17:22:49.268Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "payload",
"vendor": "payloadcms",
"versions": [
{
"status": "affected",
"version": "\u003c 3.90.0"
},
{
"status": "affected",
"version": "\u003e= 4.0.0-canary.0, \u003c 4.0.0-canary.34"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, querying a readable collection with a relationship to another collection can expose information about related documents protected by access.read where constraints. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "NONE"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-862",
"description": "CWE-862: Missing Authorization",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-06T16:15:03.763Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/payloadcms/payload/security/advisories/GHSA-7c34-32v3-j575",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/payloadcms/payload/security/advisories/GHSA-7c34-32v3-j575"
},
{
"name": "https://github.com/payloadcms/payload/commit/94059cf4bc6170ce88453015c0c6551329ae3982",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/payloadcms/payload/commit/94059cf4bc6170ce88453015c0c6551329ae3982"
},
{
"name": "https://github.com/payloadcms/payload/releases/tag/v3.90.0",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/payloadcms/payload/releases/tag/v3.90.0"
}
],
"source": {
"advisory": "GHSA-7c34-32v3-j575",
"discovery": "UNKNOWN"
},
"title": "Payload relationship-query authorization bypass"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-105852",
"datePublished": "2026-10-06T16:15:03.763Z",
"dateReserved": "2026-10-05T23:06:29.748Z",
"dateUpdated": "2026-10-06T17:22:49.268Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-105851 (GCVE-0-2026-105851)
Vulnerability from nvd – Published: 2026-10-06 16:13 – Updated: 2026-10-06 17:39
VLAI
EPSS
VEX
Title
Payload: Field access control bypass on auth collections
Summary
Payload is a free and open source headless content management system. In versions from 3.0.0 before 3.90.0 and canary versions before 4.0.0-canary.34, the duplicate operation copies values from a source document even when a field is hidden or its access.read or access.create rule rejects that value for the caller. The disableDuplicate setting does not prevent this access-control bypass. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
Severity
SSVC
Exploitation: none
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-06 17:34 UTC
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://github.com/payloadcms/payload/security/ad… | x_refsource_CONFIRM |
| https://github.com/payloadcms/payload/commit/099e… | x_refsource_MISC |
| https://github.com/payloadcms/payload/releases/ta… | x_refsource_MISC |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| payloadcms | payload |
Affected:
> 3.0.0, < 3.90.0
Affected: > 4.0.0-canary.0, < 4.0.0-canary.34 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-105851",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-06T17:34:36.004571Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-06T17:39:29.558Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "payload",
"vendor": "payloadcms",
"versions": [
{
"status": "affected",
"version": "\u003e 3.0.0, \u003c 3.90.0"
},
{
"status": "affected",
"version": "\u003e 4.0.0-canary.0, \u003c 4.0.0-canary.34"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Payload is a free and open source headless content management system. In versions from 3.0.0 before 3.90.0 and canary versions before 4.0.0-canary.34, the duplicate operation copies values from a source document even when a field is hidden or its access.read or access.create rule rejects that value for the caller. The disableDuplicate setting does not prevent this access-control bypass. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 9.3,
"baseSeverity": "CRITICAL",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "HIGH",
"subIntegrityImpact": "HIGH",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "HIGH"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-284",
"description": "CWE-284: Improper Access Control",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-863",
"description": "CWE-863: Incorrect Authorization",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-06T16:13:11.367Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/payloadcms/payload/security/advisories/GHSA-vc4h-q48j-5hcx",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/payloadcms/payload/security/advisories/GHSA-vc4h-q48j-5hcx"
},
{
"name": "https://github.com/payloadcms/payload/commit/099ef12e2682f076aa8e8d0ccb790536b4e1027f",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/payloadcms/payload/commit/099ef12e2682f076aa8e8d0ccb790536b4e1027f"
},
{
"name": "https://github.com/payloadcms/payload/releases/tag/v3.90.0",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/payloadcms/payload/releases/tag/v3.90.0"
}
],
"source": {
"advisory": "GHSA-vc4h-q48j-5hcx",
"discovery": "UNKNOWN"
},
"title": "Payload: Field access control bypass on auth collections"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-105851",
"datePublished": "2026-10-06T16:13:11.367Z",
"dateReserved": "2026-10-05T23:06:29.748Z",
"dateUpdated": "2026-10-06T17:39:29.558Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-105850 (GCVE-0-2026-105850)
Vulnerability from nvd – Published: 2026-10-06 16:11 – Updated: 2026-10-06 16:28
VLAI
EPSS
VEX
Title
Payload: Order confirmation validation issue in Payload Ecommerce
Summary
Payload is a free and open source headless content management system. In @payloadcms/plugin-ecommerce versions before 3.90.0 and canary versions before 4.0.0-canary.34, use of the Stripe payment adapter can allow a Stripe order confirmation to be processed more than once under certain conditions. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
Severity
SSVC
Exploitation: none
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-06 16:28 UTC
CWE
- CWE-837 - Improper Enforcement of a Single, Unique Action
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://github.com/payloadcms/payload/security/ad… | x_refsource_CONFIRM |
| https://github.com/payloadcms/payload/commit/6c0c… | x_refsource_MISC |
| https://github.com/payloadcms/payload/releases/ta… | x_refsource_MISC |
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| payloadcms | payload |
Affected:
< 3.90.0
Affected: >= 4.0.0-canary.0, < 4.0.0-canary.34 |
|
| @payloadcms | plugin-ecommerce |
Affected:
< 3.90.0
Affected: >= 4.0.0-canary.0, < 4.0.0-canary.34 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-105850",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-06T16:28:14.279337Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-06T16:28:23.101Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "payload",
"vendor": "payloadcms",
"versions": [
{
"status": "affected",
"version": "\u003c 3.90.0"
},
{
"status": "affected",
"version": "\u003e= 4.0.0-canary.0, \u003c 4.0.0-canary.34"
}
]
},
{
"product": "plugin-ecommerce",
"vendor": "@payloadcms",
"versions": [
{
"status": "affected",
"version": "\u003c 3.90.0"
},
{
"status": "affected",
"version": "\u003e= 4.0.0-canary.0, \u003c 4.0.0-canary.34"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Payload is a free and open source headless content management system. In @payloadcms/plugin-ecommerce versions before 3.90.0 and canary versions before 4.0.0-canary.34, use of the Stripe payment adapter can allow a Stripe order confirmation to be processed more than once under certain conditions. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.8,
"baseSeverity": "HIGH",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "HIGH"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-837",
"description": "CWE-837: Improper Enforcement of a Single, Unique Action",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-06T16:11:54.196Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/payloadcms/payload/security/advisories/GHSA-8r29-2mp2-pmrw",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/payloadcms/payload/security/advisories/GHSA-8r29-2mp2-pmrw"
},
{
"name": "https://github.com/payloadcms/payload/commit/6c0c4dc9b4ce1ac87b03fbb5dd7356b8559cbc4e",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/payloadcms/payload/commit/6c0c4dc9b4ce1ac87b03fbb5dd7356b8559cbc4e"
},
{
"name": "https://github.com/payloadcms/payload/releases/tag/v3.90.0",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/payloadcms/payload/releases/tag/v3.90.0"
}
],
"source": {
"advisory": "GHSA-8r29-2mp2-pmrw",
"discovery": "UNKNOWN"
},
"title": "Payload: Order confirmation validation issue in Payload Ecommerce"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-105850",
"datePublished": "2026-10-06T16:11:54.196Z",
"dateReserved": "2026-10-05T23:06:29.748Z",
"dateUpdated": "2026-10-06T16:28:23.101Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-105849 (GCVE-0-2026-105849)
Vulnerability from nvd – Published: 2026-10-06 16:09 – Updated: 2026-10-06 17:26
VLAI
EPSS
VEX
Title
Payload: API key disclosure through ordinary document reads
Summary
Payload is a free and open source headless content management system. In versions from 3.0.0 before 3.90.0 and canary versions before 4.0.0-canary.34, users with ordinary read access to other authentication documents in a collection with useAPIKey enabled can obtain active API keys and exercise the target accounts' permissions until those keys are rotated or disabled. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-06 17:26 UTC
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://github.com/payloadcms/payload/security/ad… | x_refsource_CONFIRM |
| https://github.com/payloadcms/payload/commit/880d… | x_refsource_MISC |
| https://github.com/payloadcms/payload/releases/ta… | x_refsource_MISC |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| payloadcms | payload |
Affected:
>= 3.0.0, < 3.90.0
Affected: >= 4.0.0-canary.0, < 4.0.0-canary.34 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-105849",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-06T17:26:14.965583Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-06T17:26:23.270Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "payload",
"vendor": "payloadcms",
"versions": [
{
"status": "affected",
"version": "\u003e= 3.0.0, \u003c 3.90.0"
},
{
"status": "affected",
"version": "\u003e= 4.0.0-canary.0, \u003c 4.0.0-canary.34"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Payload is a free and open source headless content management system. In versions from 3.0.0 before 3.90.0 and canary versions before 4.0.0-canary.34, users with ordinary read access to other authentication documents in a collection with useAPIKey enabled can obtain active API keys and exercise the target accounts\u0027 permissions until those keys are rotated or disabled. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 7.7,
"baseSeverity": "HIGH",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-201",
"description": "CWE-201: Insertion of Sensitive Information Into Sent Data",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-862",
"description": "CWE-862: Missing Authorization",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-06T16:09:49.402Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/payloadcms/payload/security/advisories/GHSA-238x-w2j9-gwwr",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/payloadcms/payload/security/advisories/GHSA-238x-w2j9-gwwr"
},
{
"name": "https://github.com/payloadcms/payload/commit/880d2e900be22cd66a9e939f2b3e702fa413180f",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/payloadcms/payload/commit/880d2e900be22cd66a9e939f2b3e702fa413180f"
},
{
"name": "https://github.com/payloadcms/payload/releases/tag/v3.90.0",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/payloadcms/payload/releases/tag/v3.90.0"
}
],
"source": {
"advisory": "GHSA-238x-w2j9-gwwr",
"discovery": "UNKNOWN"
},
"title": "Payload: API key disclosure through ordinary document reads"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-105849",
"datePublished": "2026-10-06T16:09:49.402Z",
"dateReserved": "2026-10-05T23:06:29.747Z",
"dateUpdated": "2026-10-06T17:26:23.270Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-105848 (GCVE-0-2026-105848)
Vulnerability from nvd – Published: 2026-10-06 16:07 – Updated: 2026-10-09 01:10
VLAI
EPSS
VEX
Title
Payload: Insufficient Access Control in Stripe REST Proxy
Summary
Payload is a free and open source headless content management system. In @payloadcms/plugin-stripe versions before 3.90.0 and canary versions before 4.0.0-canary.34, an authenticated user who can reach the enabled optional Stripe REST proxy can perform unintended Stripe operations. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-09 01:10 UTC
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://github.com/payloadcms/payload/security/ad… | x_refsource_CONFIRM |
| https://github.com/payloadcms/payload/commit/2f94… | x_refsource_MISC |
| https://github.com/payloadcms/payload/releases/ta… | x_refsource_MISC |
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| payloadcms | payload |
Affected:
< 3.90.0
Affected: >= 4.0.0-canary.0, < 4.0.0-canary.34 |
|
| @payloadcms | plugin-stripe |
Affected:
< 3.90.0
Affected: >= 4.0.0-canary.0, < 4.0.0-canary.34 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-105848",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-09T01:10:12.482093Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-09T01:10:22.727Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "payload",
"vendor": "payloadcms",
"versions": [
{
"status": "affected",
"version": "\u003c 3.90.0"
},
{
"status": "affected",
"version": "\u003e= 4.0.0-canary.0, \u003c 4.0.0-canary.34"
}
]
},
{
"product": "plugin-stripe",
"vendor": "@payloadcms",
"versions": [
{
"status": "affected",
"version": "\u003c 3.90.0"
},
{
"status": "affected",
"version": "\u003e= 4.0.0-canary.0, \u003c 4.0.0-canary.34"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Payload is a free and open source headless content management system. In @payloadcms/plugin-stripe versions before 3.90.0 and canary versions before 4.0.0-canary.34, an authenticated user who can reach the enabled optional Stripe REST proxy can perform unintended Stripe operations. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 6.4,
"baseSeverity": "MEDIUM",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "HIGH",
"subIntegrityImpact": "HIGH",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-749",
"description": "CWE-749: Exposed Dangerous Method or Function",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-862",
"description": "CWE-862: Missing Authorization",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-06T16:07:53.896Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/payloadcms/payload/security/advisories/GHSA-r9v2-gg2j-22q5",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/payloadcms/payload/security/advisories/GHSA-r9v2-gg2j-22q5"
},
{
"name": "https://github.com/payloadcms/payload/commit/2f94a4205e5ba3ec0e91c92ed54f24f429826dd0",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/payloadcms/payload/commit/2f94a4205e5ba3ec0e91c92ed54f24f429826dd0"
},
{
"name": "https://github.com/payloadcms/payload/releases/tag/v3.90.0",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/payloadcms/payload/releases/tag/v3.90.0"
}
],
"source": {
"advisory": "GHSA-r9v2-gg2j-22q5",
"discovery": "UNKNOWN"
},
"title": "Payload: Insufficient Access Control in Stripe REST Proxy"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-105848",
"datePublished": "2026-10-06T16:07:53.896Z",
"dateReserved": "2026-10-05T23:06:29.747Z",
"dateUpdated": "2026-10-09T01:10:22.727Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-105847 (GCVE-0-2026-105847)
Vulnerability from nvd – Published: 2026-10-06 16:02 – Updated: 2026-10-06 17:22
VLAI
EPSS
VEX
Title
Payload: Polymorphic join queries could disclose hidden fields
Summary
Payload is a free and open source headless content management system. In versions from 3.0.0 before 3.90.0 and canary versions before 4.0.0-canary.34, a user who can query a collection with a polymorphic join to sensitive fields can infer hidden or read-restricted values, including password-reset tokens, through polymorphic join filters. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-06 17:22 UTC
CWE
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://github.com/payloadcms/payload/security/ad… | x_refsource_CONFIRM |
| https://github.com/payloadcms/payload/commit/caa3… | x_refsource_MISC |
| https://github.com/payloadcms/payload/releases/ta… | x_refsource_MISC |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| payloadcms | payload |
Affected:
>= 3.0.0, < 3.90.0
Affected: >= 4.0.0-canary.0, < 4.0.0-canary.34 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-105847",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-06T17:22:09.250635Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-06T17:22:16.944Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "payload",
"vendor": "payloadcms",
"versions": [
{
"status": "affected",
"version": "\u003e= 3.0.0, \u003c 3.90.0"
},
{
"status": "affected",
"version": "\u003e= 4.0.0-canary.0, \u003c 4.0.0-canary.34"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Payload is a free and open source headless content management system. In versions from 3.0.0 before 3.90.0 and canary versions before 4.0.0-canary.34, a user who can query a collection with a polymorphic join to sensitive fields can infer hidden or read-restricted values, including password-reset tokens, through polymorphic join filters. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 7.1,
"baseSeverity": "HIGH",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "NONE"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-200",
"description": "CWE-200: Exposure of Sensitive Information to an Unauthorized Actor",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-639",
"description": "CWE-639: Authorization Bypass Through User-Controlled Key",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-06T16:02:55.117Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/payloadcms/payload/security/advisories/GHSA-fpww-c55p-cjv6",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/payloadcms/payload/security/advisories/GHSA-fpww-c55p-cjv6"
},
{
"name": "https://github.com/payloadcms/payload/commit/caa3f69b5aecc6e7c2b459ed87972cbca9f33ee5",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/payloadcms/payload/commit/caa3f69b5aecc6e7c2b459ed87972cbca9f33ee5"
},
{
"name": "https://github.com/payloadcms/payload/releases/tag/v3.90.0",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/payloadcms/payload/releases/tag/v3.90.0"
}
],
"source": {
"advisory": "GHSA-fpww-c55p-cjv6",
"discovery": "UNKNOWN"
},
"title": "Payload: Polymorphic join queries could disclose hidden fields"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-105847",
"datePublished": "2026-10-06T16:02:55.117Z",
"dateReserved": "2026-10-05T23:06:29.747Z",
"dateUpdated": "2026-10-06T17:22:16.944Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-105846 (GCVE-0-2026-105846)
Vulnerability from nvd – Published: 2026-10-06 16:01 – Updated: 2026-10-06 17:39
VLAI
EPSS
VEX
Title
Payload: Untrusted redirect URL parameter exploit
Summary
Payload is a free and open source headless content management system. In versions from 3.40.0 before 3.88.0 and canary versions before 4.0.0-canary.27, an attacker can craft a redirect URL parameter that sends a guest user to an untrusted destination after the authentication flow completes. This issue is fixed in versions 3.88.0 and 4.0.0-canary.27.
Severity
6.1 (Medium)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-06 17:34 UTC
CWE
- CWE-601 - URL Redirection to Untrusted Site ('Open Redirect')
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://github.com/payloadcms/payload/security/ad… | x_refsource_CONFIRM |
| https://github.com/payloadcms/payload/commit/a742… | x_refsource_MISC |
| https://github.com/payloadcms/payload/releases/ta… | x_refsource_MISC |
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| payloadcms | payload |
Affected:
>= 3.40.0, < 3.88.0
Affected: >= 4.0.0-canary.0, < 4.0.0-canary.27 |
|
| @payloadcms | next |
Affected:
>= 3.31.0, < 3.88.0
Affected: >= 4.0.0-canary.0, < 4.0.0-canary.27 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-105846",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-06T17:34:11.494178Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-06T17:39:36.818Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "payload",
"vendor": "payloadcms",
"versions": [
{
"status": "affected",
"version": "\u003e= 3.40.0, \u003c 3.88.0"
},
{
"status": "affected",
"version": "\u003e= 4.0.0-canary.0, \u003c 4.0.0-canary.27"
}
]
},
{
"product": "next",
"vendor": "@payloadcms",
"versions": [
{
"status": "affected",
"version": "\u003e= 3.31.0, \u003c 3.88.0"
},
{
"status": "affected",
"version": "\u003e= 4.0.0-canary.0, \u003c 4.0.0-canary.27"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Payload is a free and open source headless content management system. In versions from 3.40.0 before 3.88.0 and canary versions before 4.0.0-canary.27, an attacker can craft a redirect URL parameter that sends a guest user to an untrusted destination after the authentication flow completes. This issue is fixed in versions 3.88.0 and 4.0.0-canary.27."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 6.1,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "CHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-601",
"description": "CWE-601: URL Redirection to Untrusted Site (\u0027Open Redirect\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-06T16:01:30.370Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/payloadcms/payload/security/advisories/GHSA-w84c-53h3-mc2g",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/payloadcms/payload/security/advisories/GHSA-w84c-53h3-mc2g"
},
{
"name": "https://github.com/payloadcms/payload/commit/a742140ab4fca3160f7f83e9e7d996552ffc3b5a",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/payloadcms/payload/commit/a742140ab4fca3160f7f83e9e7d996552ffc3b5a"
},
{
"name": "https://github.com/payloadcms/payload/releases/tag/v3.88.0",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/payloadcms/payload/releases/tag/v3.88.0"
}
],
"source": {
"advisory": "GHSA-w84c-53h3-mc2g",
"discovery": "UNKNOWN"
},
"title": "Payload: Untrusted redirect URL parameter exploit"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-105846",
"datePublished": "2026-10-06T16:01:30.370Z",
"dateReserved": "2026-10-05T23:06:29.747Z",
"dateUpdated": "2026-10-06T17:39:36.818Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-106100 (GCVE-0-2026-106100)
Vulnerability from cvelistv5 – Published: 2026-10-06 16:56 – Updated: 2026-10-06 17:28
VLAI
EPSS
VEX
Title
Payload: Field-level write access bypass in Payload on MongoDB
Summary
Payload is a free and open source headless content management system. In @payloadcms/db-mongodb versions before 3.87.0 and canary versions before 4.0.0-canary.20, an authenticated user who can update a document can modify fields that field-level write access control does not permit that user to change. The Postgres and SQLite adapters are not affected. This issue is fixed in versions 3.87.0 and 4.0.0-canary.20.
Severity
7.1 (High)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-06 17:28 UTC
CWE
Assigner
References
4 references
| URL | Tags |
|---|---|
| https://github.com/payloadcms/payload/security/ad… | x_refsource_CONFIRM |
| https://github.com/payloadcms/payload/commit/2a69… | x_refsource_MISC |
| https://github.com/payloadcms/payload/commit/8f77… | x_refsource_MISC |
| https://github.com/payloadcms/payload/releases/ta… | x_refsource_MISC |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| payloadcms | payload |
Affected:
< 3.87.0
Affected: >= 4.0.0-canary.0, < 4.0.0-canary.20 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-106100",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-06T17:28:47.529744Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-06T17:28:55.961Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "payload",
"vendor": "payloadcms",
"versions": [
{
"status": "affected",
"version": "\u003c 3.87.0"
},
{
"status": "affected",
"version": "\u003e= 4.0.0-canary.0, \u003c 4.0.0-canary.20"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Payload is a free and open source headless content management system. In @payloadcms/db-mongodb versions before 3.87.0 and canary versions before 4.0.0-canary.20, an authenticated user who can update a document can modify fields that field-level write access control does not permit that user to change. The Postgres and SQLite adapters are not affected. This issue is fixed in versions 3.87.0 and 4.0.0-canary.20."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 7.1,
"baseSeverity": "HIGH",
"confidentialityImpact": "LOW",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-639",
"description": "CWE-639: Authorization Bypass Through User-Controlled Key",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-915",
"description": "CWE-915: Improperly Controlled Modification of Dynamically-Determined Object Attributes",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-06T16:56:55.715Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/payloadcms/payload/security/advisories/GHSA-4ww4-68q3-h7g5",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/payloadcms/payload/security/advisories/GHSA-4ww4-68q3-h7g5"
},
{
"name": "https://github.com/payloadcms/payload/commit/2a69863deb0e3c87e36c1b3b17ab2d5b02fcb941",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/payloadcms/payload/commit/2a69863deb0e3c87e36c1b3b17ab2d5b02fcb941"
},
{
"name": "https://github.com/payloadcms/payload/commit/8f77dffa9552885ec2710768cfee15b57e389935",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/payloadcms/payload/commit/8f77dffa9552885ec2710768cfee15b57e389935"
},
{
"name": "https://github.com/payloadcms/payload/releases/tag/v3.87.0",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/payloadcms/payload/releases/tag/v3.87.0"
}
],
"source": {
"advisory": "GHSA-4ww4-68q3-h7g5",
"discovery": "UNKNOWN"
},
"title": "Payload: Field-level write access bypass in Payload on MongoDB"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-106100",
"datePublished": "2026-10-06T16:56:55.715Z",
"dateReserved": "2026-10-06T15:33:55.332Z",
"dateUpdated": "2026-10-06T17:28:55.961Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-105868 (GCVE-0-2026-105868)
Vulnerability from cvelistv5 – Published: 2026-10-06 16:51 – Updated: 2026-10-09 01:17
VLAI
EPSS
VEX
Title
Payload: Uploaded XML files could execute same-origin JavaScript
Summary
Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, local upload configurations that accept XML files can store an XML file and stylesheet that execute JavaScript in the Payload origin when a logged-in user opens the file. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
Severity
SSVC
Exploitation: none
Automatable: yes
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-09 01:17 UTC
CWE
- CWE-434 - Unrestricted Upload of File with Dangerous Type
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://github.com/payloadcms/payload/security/ad… | x_refsource_CONFIRM |
| https://github.com/payloadcms/payload/commit/a8c3… | x_refsource_MISC |
| https://github.com/payloadcms/payload/releases/ta… | x_refsource_MISC |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| payloadcms | payload |
Affected:
< 3.90.0
Affected: >= 4.0.0-canary.0, < 4.0.0-canary.34 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-105868",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-09T01:17:27.846201Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-09T01:17:45.783Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "payload",
"vendor": "payloadcms",
"versions": [
{
"status": "affected",
"version": "\u003c 3.90.0"
},
{
"status": "affected",
"version": "\u003e= 4.0.0-canary.0, \u003c 4.0.0-canary.34"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, local upload configurations that accept XML files can store an XML file and stylesheet that execute JavaScript in the Payload origin when a logged-in user opens the file. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.6,
"baseSeverity": "HIGH",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "PASSIVE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-434",
"description": "CWE-434: Unrestricted Upload of File with Dangerous Type",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-06T16:51:34.054Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/payloadcms/payload/security/advisories/GHSA-9qpg-3cf8-w33x",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/payloadcms/payload/security/advisories/GHSA-9qpg-3cf8-w33x"
},
{
"name": "https://github.com/payloadcms/payload/commit/a8c3a8e8e2680c96ec4f66f5b3854c5df6c35adf",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/payloadcms/payload/commit/a8c3a8e8e2680c96ec4f66f5b3854c5df6c35adf"
},
{
"name": "https://github.com/payloadcms/payload/releases/tag/v3.90.0",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/payloadcms/payload/releases/tag/v3.90.0"
}
],
"source": {
"advisory": "GHSA-9qpg-3cf8-w33x",
"discovery": "UNKNOWN"
},
"title": "Payload: Uploaded XML files could execute same-origin JavaScript"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-105868",
"datePublished": "2026-10-06T16:51:34.054Z",
"dateReserved": "2026-10-05T23:06:29.748Z",
"dateUpdated": "2026-10-09T01:17:45.783Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-105867 (GCVE-0-2026-105867)
Vulnerability from cvelistv5 – Published: 2026-10-06 16:49 – Updated: 2026-10-06 17:24
VLAI
EPSS
VEX
Title
Payload: Client uploads could overwrite S3 objects
Summary
Payload is a free and open source headless content management system. In @payloadcms/storage-s3 versions before 3.90.0 and canary versions before 4.0.0-canary.34, an authenticated user can overwrite an existing S3 object belonging to another upload collection when client uploads are enabled for multiple collections sharing a bucket and useCompositePrefixes is false or unset. This bypasses the target collection's access controls and prior file validation. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-06 17:24 UTC
CWE
- CWE-639 - Authorization Bypass Through User-Controlled Key
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://github.com/payloadcms/payload/security/ad… | x_refsource_CONFIRM |
| https://github.com/payloadcms/payload/commit/2df8… | x_refsource_MISC |
| https://github.com/payloadcms/payload/releases/ta… | x_refsource_MISC |
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| payloadcms | payload |
Affected:
< 3.90.0
Affected: >= 4.0.0-canary.0, < 4.0.0-canary.34 |
|
| @payloadcms | storage-s3 |
Affected:
< 3.90.0
Affected: >= 4.0.0-canary.0, < 4.0.0-canary.34 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-105867",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-06T17:24:30.442506Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-06T17:24:39.913Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "payload",
"vendor": "payloadcms",
"versions": [
{
"status": "affected",
"version": "\u003c 3.90.0"
},
{
"status": "affected",
"version": "\u003e= 4.0.0-canary.0, \u003c 4.0.0-canary.34"
}
]
},
{
"product": "storage-s3",
"vendor": "@payloadcms",
"versions": [
{
"status": "affected",
"version": "\u003c 3.90.0"
},
{
"status": "affected",
"version": "\u003e= 4.0.0-canary.0, \u003c 4.0.0-canary.34"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Payload is a free and open source headless content management system. In @payloadcms/storage-s3 versions before 3.90.0 and canary versions before 4.0.0-canary.34, an authenticated user can overwrite an existing S3 object belonging to another upload collection when client uploads are enabled for multiple collections sharing a bucket and useCompositePrefixes is false or unset. This bypasses the target collection\u0027s access controls and prior file validation. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 7.1,
"baseSeverity": "HIGH",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "LOW",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "HIGH"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-639",
"description": "CWE-639: Authorization Bypass Through User-Controlled Key",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-06T16:49:12.532Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/payloadcms/payload/security/advisories/GHSA-7vg8-29qx-jgj8",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/payloadcms/payload/security/advisories/GHSA-7vg8-29qx-jgj8"
},
{
"name": "https://github.com/payloadcms/payload/commit/2df8238fbf17edfce335c399b90bf524ba9906a2",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/payloadcms/payload/commit/2df8238fbf17edfce335c399b90bf524ba9906a2"
},
{
"name": "https://github.com/payloadcms/payload/releases/tag/v3.90.0",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/payloadcms/payload/releases/tag/v3.90.0"
}
],
"source": {
"advisory": "GHSA-7vg8-29qx-jgj8",
"discovery": "UNKNOWN"
},
"title": "Payload: Client uploads could overwrite S3 objects"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-105867",
"datePublished": "2026-10-06T16:49:12.532Z",
"dateReserved": "2026-10-05T23:06:29.748Z",
"dateUpdated": "2026-10-06T17:24:39.913Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-105866 (GCVE-0-2026-105866)
Vulnerability from cvelistv5 – Published: 2026-10-06 16:46 – Updated: 2026-10-06 17:39
VLAI
EPSS
VEX
Title
Payload: Unauthenticated account-lockout denial of service
Summary
Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, an unauthenticated attacker who knows an account email address or username can abuse the account lockout mechanism of a local-authentication collection to prevent that account from signing in. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
Severity
SSVC
Exploitation: none
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-06 17:34 UTC
CWE
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://github.com/payloadcms/payload/security/ad… | x_refsource_CONFIRM |
| https://github.com/payloadcms/payload/commit/1c46… | x_refsource_MISC |
| https://github.com/payloadcms/payload/releases/ta… | x_refsource_MISC |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| payloadcms | payload |
Affected:
< 3.90.0
Affected: >= 4.0.0-canary.0, < 4.0.0-canary.34 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-105866",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-06T17:34:37.543263Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-06T17:39:09.686Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "payload",
"vendor": "payloadcms",
"versions": [
{
"status": "affected",
"version": "\u003c 3.90.0"
},
{
"status": "affected",
"version": "\u003e= 4.0.0-canary.0, \u003c 4.0.0-canary.34"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, an unauthenticated attacker who knows an account email address or username can abuse the account lockout mechanism of a local-authentication collection to prevent that account from signing in. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "LOW",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-307",
"description": "CWE-307: Improper Restriction of Excessive Authentication Attempts",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-645",
"description": "CWE-645: Overly Restrictive Account Lockout Mechanism",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-06T16:46:31.069Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/payloadcms/payload/security/advisories/GHSA-v5gf-vpjc-pc7w",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/payloadcms/payload/security/advisories/GHSA-v5gf-vpjc-pc7w"
},
{
"name": "https://github.com/payloadcms/payload/commit/1c46204a73a0a9f988a80c52690eee5a4ada3cf1",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/payloadcms/payload/commit/1c46204a73a0a9f988a80c52690eee5a4ada3cf1"
},
{
"name": "https://github.com/payloadcms/payload/releases/tag/v3.90.0",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/payloadcms/payload/releases/tag/v3.90.0"
}
],
"source": {
"advisory": "GHSA-v5gf-vpjc-pc7w",
"discovery": "UNKNOWN"
},
"title": "Payload: Unauthenticated account-lockout denial of service"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-105866",
"datePublished": "2026-10-06T16:46:31.069Z",
"dateReserved": "2026-10-05T23:06:29.748Z",
"dateUpdated": "2026-10-06T17:39:09.686Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-105865 (GCVE-0-2026-105865)
Vulnerability from cvelistv5 – Published: 2026-10-06 16:45 – Updated: 2026-10-06 17:11
VLAI
EPSS
VEX
Title
Payload: Incomplete validation during the upload file lifecycle
Summary
Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, an authenticated user who can update or delete uploads stored locally can cause file cleanup to remove unintended files outside the configured upload directory, resulting in data loss or service disruption. Deployments that restrict upload management to trusted users are less exposed. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
Severity
8.1 (High)
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-06 17:10 UTC
CWE
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://github.com/payloadcms/payload/security/ad… | x_refsource_CONFIRM |
| https://github.com/payloadcms/payload/commit/6b74… | x_refsource_MISC |
| https://github.com/payloadcms/payload/releases/ta… | x_refsource_MISC |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| payloadcms | payload |
Affected:
< 3.90.0
Affected: >= 4.0.0-canary.0, < 4.0.0-canary.34 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-105865",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-06T17:10:04.066384Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-06T17:11:18.423Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "payload",
"vendor": "payloadcms",
"versions": [
{
"status": "affected",
"version": "\u003c 3.90.0"
},
{
"status": "affected",
"version": "\u003e= 4.0.0-canary.0, \u003c 4.0.0-canary.34"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, an authenticated user who can update or delete uploads stored locally can cause file cleanup to remove unintended files outside the configured upload directory, resulting in data loss or service disruption. Deployments that restrict upload management to trusted users are less exposed. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.1,
"baseSeverity": "HIGH",
"confidentialityImpact": "NONE",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-22",
"description": "CWE-22: Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-73",
"description": "CWE-73: External Control of File Name or Path",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-06T16:45:09.932Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/payloadcms/payload/security/advisories/GHSA-p223-2wr2-j562",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/payloadcms/payload/security/advisories/GHSA-p223-2wr2-j562"
},
{
"name": "https://github.com/payloadcms/payload/commit/6b74418f628fa633c2f297e5919a9f91b383dc11",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/payloadcms/payload/commit/6b74418f628fa633c2f297e5919a9f91b383dc11"
},
{
"name": "https://github.com/payloadcms/payload/releases/tag/v3.90.0",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/payloadcms/payload/releases/tag/v3.90.0"
}
],
"source": {
"advisory": "GHSA-p223-2wr2-j562",
"discovery": "UNKNOWN"
},
"title": "Payload: Incomplete validation during the upload file lifecycle"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-105865",
"datePublished": "2026-10-06T16:45:09.932Z",
"dateReserved": "2026-10-05T23:06:29.748Z",
"dateUpdated": "2026-10-06T17:11:18.423Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-105864 (GCVE-0-2026-105864)
Vulnerability from cvelistv5 – Published: 2026-10-06 16:42 – Updated: 2026-10-06 17:25
VLAI
EPSS
VEX
Title
Payload: Cross-tenant create in @payloadcms/plugin-multi-tenant
Summary
Payload is a free and open source headless content management system. In @payloadcms/plugin-multi-tenant versions before 3.90.0 and canary versions before 4.0.0-canary.34, an authenticated user limited to one tenant can create a record in another tenant when at least one tenant-enabled collection exists. Reads and direct edits of existing documents in the target tenant are not bypassed. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-06 17:25 UTC
CWE
- CWE-863 - Incorrect Authorization
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://github.com/payloadcms/payload/security/ad… | x_refsource_CONFIRM |
| https://github.com/payloadcms/payload/commit/b8fc… | x_refsource_MISC |
| https://github.com/payloadcms/payload/releases/ta… | x_refsource_MISC |
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| payloadcms | payload |
Affected:
< 3.90.0
Affected: >= 4.0.0-canary.0, < 4.0.0-canary.34 |
|
| @payloadcms | plugin-multi-tenant |
Affected:
< 3.90.0
Affected: >= 4.0.0-canary.0, < 4.0.0-canary.34 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-105864",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-06T17:25:08.590502Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-06T17:25:18.758Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "payload",
"vendor": "payloadcms",
"versions": [
{
"status": "affected",
"version": "\u003c 3.90.0"
},
{
"status": "affected",
"version": "\u003e= 4.0.0-canary.0, \u003c 4.0.0-canary.34"
}
]
},
{
"product": "plugin-multi-tenant",
"vendor": "@payloadcms",
"versions": [
{
"status": "affected",
"version": "\u003c 3.90.0"
},
{
"status": "affected",
"version": "\u003e= 4.0.0-canary.0, \u003c 4.0.0-canary.34"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Payload is a free and open source headless content management system. In @payloadcms/plugin-multi-tenant versions before 3.90.0 and canary versions before 4.0.0-canary.34, an authenticated user limited to one tenant can create a record in another tenant when at least one tenant-enabled collection exists. Reads and direct edits of existing documents in the target tenant are not bypassed. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "LOW"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-863",
"description": "CWE-863: Incorrect Authorization",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-06T16:42:27.942Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/payloadcms/payload/security/advisories/GHSA-xhm9-gwgw-3q2q",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/payloadcms/payload/security/advisories/GHSA-xhm9-gwgw-3q2q"
},
{
"name": "https://github.com/payloadcms/payload/commit/b8fc06a18afb6974dc07f95ac1e541c716e5926b",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/payloadcms/payload/commit/b8fc06a18afb6974dc07f95ac1e541c716e5926b"
},
{
"name": "https://github.com/payloadcms/payload/releases/tag/v3.90.0",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/payloadcms/payload/releases/tag/v3.90.0"
}
],
"source": {
"advisory": "GHSA-xhm9-gwgw-3q2q",
"discovery": "UNKNOWN"
},
"title": "Payload: Cross-tenant create in @payloadcms/plugin-multi-tenant"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-105864",
"datePublished": "2026-10-06T16:42:27.942Z",
"dateReserved": "2026-10-05T23:06:29.748Z",
"dateUpdated": "2026-10-06T17:25:18.758Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}