Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-105859: Payload CMS allows unauthorized document changes
CVE-2026-105859 · published 3 days ago
Summary
The open‑source Payload content system (versions before 3.90.0 and early canary builds) lets an attacker send a specially crafted request that can alter stored documents without checking who is allowed to make those changes. This could let someone modify or reorder content they shouldn’t control. Upgrade to version 3.90.0 or later (or the 4.0.0‑canary.34 release) to close the gap.
What to do
- Update payload to version 3.90.0.
- Update payload to version 4.0.0-canary.34.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | payloadcms | payload | < 3.90.0 |
| npm | – | payload |
< 3.90.0 >= 4.0.0-canary.0, < 4.0.0-canary.34 Fix: upgrade to 3.90.0
|
Original advisory text
Payload: Unauthorized update to collection documents
Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, an attacker can submit a request to a specific update endpoint that modifies collection documents without enforcing collection or field-level access control when orderable is enabled on a collection or join field. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
References
- https://github.com/advisories/GHSA-f7hx-52q9-hcrf
- https://github.com/payloadcms/payload Product
- https://github.com/payloadcms/payload/security/advisories/GHSA-f7hx-52q9-hcrf
- https://github.com/payloadcms/payload/commit/36fa9af73dd04fa59f4b4a06d11454538c4...
- https://github.com/payloadcms/payload/releases/tag/v3.90.0
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/105xxx/CVE-2026-1058... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-105859 Vendor Advisory
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically (estimated)
- Gives an attacker full control (estimated)
Type
CWE-639Authorization Bypass Through User-Controlled Key
CWE-862Missing Authorization
Timeline
Published6 Oct 2026
Updated9 Oct 2026
First seen6 Oct 2026
Sources
CVE-2026-105859 · NVD
CVE-2026-105859 · MITRE
CVE-2026-105859 · OSV
GHSA-f7hx-52q9-hcrf · GHSA
GHSA-f7hx-52q9-hcrf · OSV
Track software like this
Free during beta