Remote Code Execution Risk in Payload CMS Versions by Payload Inc.
CVE-2026-105844

9.3CRITICAL

Key Information:

Vendor

Payloadcms

Vendor
CVE Published:
6 October 2026

What is CVE-2026-105844?

In Payload CMS versions prior to 3.88.0 and canary versions before 4.0.0-canary.27, a vulnerability exists due to the improper handling of prototype-sensitive field paths. Specifically, when the @payloadcms/plugin-import-export feature is enabled, unauthenticated users can exploit this weakness, leading to unintended application behavior and the potential for remote code execution. This issue has been addressed in the latest releases, and it is crucial for users to update to versions 3.88.0 and 4.0.0-canary.27 or later to ensure their systems remain secure.

Affected Version(s)

payload >= 3.0.0, < 3.88.0 < 3.0.0, 3.88.0

payload >= 4.0.0-canary.0, < 4.0.0-canary.27 < 4.0.0-canary.0, 4.0.0-canary.27

plugin-import-export >= 3.0.0, < 3.88.0 < 3.0.0, 3.88.0

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.