Remote Code Execution Risk in Payload CMS Versions by Payload Inc.
CVE-2026-105844
9.3CRITICAL
What is CVE-2026-105844?
In Payload CMS versions prior to 3.88.0 and canary versions before 4.0.0-canary.27, a vulnerability exists due to the improper handling of prototype-sensitive field paths. Specifically, when the @payloadcms/plugin-import-export feature is enabled, unauthenticated users can exploit this weakness, leading to unintended application behavior and the potential for remote code execution. This issue has been addressed in the latest releases, and it is crucial for users to update to versions 3.88.0 and 4.0.0-canary.27 or later to ensure their systems remain secure.
Affected Version(s)
payload >= 3.0.0, < 3.88.0 < 3.0.0, 3.88.0
payload >= 4.0.0-canary.0, < 4.0.0-canary.27 < 4.0.0-canary.0, 4.0.0-canary.27
plugin-import-export >= 3.0.0, < 3.88.0 < 3.0.0, 3.88.0
