Authentication Vulnerability in Payload CMS by Payload
CVE-2026-105863

9.2CRITICAL

Key Information:

Vendor

Payloadcms

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-105863?

A vulnerability exists in Payload CMS affecting versions between 3.0.0 and 3.90.0. This flaw allows for a custom field option to unintentionally influence authentication claims in login tokens, compromising the integrity of user authentication. Users are advised to upgrade to version 3.90.0, where this issue has been effectively addressed. For more details, please refer to the provided references.

Affected Version(s)

payload >= 3.0.0, < 3.90.0 < 3.0.0, 3.90.0

payload >= 4.0.0-canary.0, < 4.0.0-canary.34 < 4.0.0-canary.0, 4.0.0-canary.34

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.