Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-105844: Payload import-export plugin allows unauthenticated code execution

CVE-2026-105844 · published 3 days ago
Summary

The free Payload content system, when the import‑export add‑on is turned on, lets anyone without a login send specially crafted data that can make the server run their own code. This affects versions before 3.88.0 and certain early 4.0.0‑canary builds. Upgrade the product to version 3.88.0 or later (or the 4.0.0‑canary.27 release) to close the gap.

What to do
  • Update payloadcms plugin-import-export to version 3.88.0.
  • Update payloadcms plugin-import-export to version 4.0.0-canary.27.
  • Update payloadcms @payloadcms/plugin-import-export to version 3.88.0.
  • Update payloadcms @payloadcms/plugin-import-export to version 4.0.0-canary.27.
Affected software
Ecosystem VendorProductAffected versions
– payloadcms payload >= 3.0.0, < 3.88.0
– @payloadcms plugin-import-export >= 3.0.0, < 3.88.0
npm payloadcms plugin-import-export >= 3.0.0, < 3.88.0
>= 4.0.0-canary.0, < 4.0.0-canary.27
Fix: upgrade to 3.88.0
npm payloadcms @payloadcms/plugin-import-export >= 3.0.0, < 3.88.0
>= 4.0.0-canary.0, < 4.0.0-canary.27
Fix: upgrade to 3.88.0
Original advisory text
Payload: Prototype pollution in Payload Import Export plugin
Payload is a free and open source headless content management system. In versions from 3.0.0 before 3.88.0 and canary versions before 4.0.0-canary.27, an unauthenticated user can submit prototype-sensitive field paths when @payloadcms/plugin-import-export is enabled, causing unintended application behavior that can lead to remote code execution. This issue is fixed in versions 3.88.0 and 4.0.0-canary.27.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.3 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-1321Prototype Pollution
Timeline
Published6 Oct 2026
Updated9 Oct 2026
First seen6 Oct 2026
Track software like this
Free during beta