Password Hashing Vulnerability in Payload CMS Versions by Payload
CVE-2026-105804
5.7MEDIUM
What is CVE-2026-105804?
Payload CMS, a free and open-source headless content management system, has a vulnerability in versions prior to 3.90.0, where it utilizes a lower-than-recommended PBKDF2 work factor for password hashing. This significantly reduces the computational effort needed to crack password hashes, potentially exposing user credentials to unauthorized access. The issue has been addressed in versions 3.90.0 and 4.0.0-canary.34, ensuring enhanced security for users.
Affected Version(s)
payload >= 3.0.0, < 3.90.0 < 3.0.0, 3.90.0
payload >= 4.0.0-canary.0, < 4.0.0-canary.34 < 4.0.0-canary.0, 4.0.0-canary.34
