Remote Code Execution Vulnerability in Payload CMS Affects Versions Before 3.90.0
CVE-2026-105858
8.1HIGH
What is CVE-2026-105858?
A vulnerability in Payload CMS allows for the execution of arbitrary code through crafted requests to the public first-register operation when local authentication is enabled and no initial user is created. This flaw affects Payload CMS versions prior to 3.90.0 and canary editions before 4.0.0-canary.34, potentially putting systems at risk if not updated to the patched versions.
Affected Version(s)
payload < 3.90.0 < 3.90.0
payload >= 4.0.0-canary.0, < 4.0.0-canary.34 < 4.0.0-canary.0, 4.0.0-canary.34
