Authentication Vulnerability in Payload CMS by Payload
CVE-2026-105863
9.2CRITICAL
What is CVE-2026-105863?
A vulnerability exists in Payload CMS affecting versions between 3.0.0 and 3.90.0. This flaw allows for a custom field option to unintentionally influence authentication claims in login tokens, compromising the integrity of user authentication. Users are advised to upgrade to version 3.90.0, where this issue has been effectively addressed. For more details, please refer to the provided references.
Affected Version(s)
payload >= 3.0.0, < 3.90.0 < 3.0.0, 3.90.0
payload >= 4.0.0-canary.0, < 4.0.0-canary.34 < 4.0.0-canary.0, 4.0.0-canary.34
