Password Hashing Vulnerability in Payload CMS Versions by Payload
CVE-2026-105804

5.7MEDIUM

Key Information:

Vendor

Payloadcms

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-105804?

Payload CMS, a free and open-source headless content management system, has a vulnerability in versions prior to 3.90.0, where it utilizes a lower-than-recommended PBKDF2 work factor for password hashing. This significantly reduces the computational effort needed to crack password hashes, potentially exposing user credentials to unauthorized access. The issue has been addressed in versions 3.90.0 and 4.0.0-canary.34, ensuring enhanced security for users.

Affected Version(s)

payload >= 3.0.0, < 3.90.0 < 3.0.0, 3.90.0

payload >= 4.0.0-canary.0, < 4.0.0-canary.34 < 4.0.0-canary.0, 4.0.0-canary.34

References

CVSS V4

Score:
5.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.