Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-105859: Payload CMS allows unauthorized document changes

CVE-2026-105859 · published 3 days ago
Summary

The open‑source Payload content system (versions before 3.90.0 and early canary builds) lets an attacker send a specially crafted request that can alter stored documents without checking who is allowed to make those changes. This could let someone modify or reorder content they shouldn’t control. Upgrade to version 3.90.0 or later (or the 4.0.0‑canary.34 release) to close the gap.

What to do
  • Update payload to version 3.90.0.
  • Update payload to version 4.0.0-canary.34.
Affected software
Ecosystem VendorProductAffected versions
– payloadcms payload < 3.90.0
npm – payload < 3.90.0
>= 4.0.0-canary.0, < 4.0.0-canary.34
Fix: upgrade to 3.90.0
Original advisory text
Payload: Unauthorized update to collection documents
Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, an attacker can submit a request to a specific update endpoint that modifies collection documents without enforcing collection or field-level access control when orderable is enabled on a collection or join field. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically (estimated)
  • Gives an attacker full control (estimated)
Severity
9.8 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-639Authorization Bypass Through User-Controlled Key
CWE-862Missing Authorization
Timeline
Published6 Oct 2026
Updated9 Oct 2026
First seen6 Oct 2026
Track software like this
Free during beta