File Cleanup Vulnerability in Payload CMS Versions Prior to 3.90.0
CVE-2026-105865

8.1HIGH

Key Information:

Vendor

Payloadcms

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-105865?

In Payload CMS, an issue exists where authenticated users, authorized to update or delete uploads, can inadvertently trigger a cleanup process that removes files outside designated upload directories. This vulnerability, affecting all versions prior to 3.90.0 and canary versions before 4.0.0-canary.34, poses a risk of unintentional data loss and potential service interruption. The impact can be mitigated by restricting upload privileges to trusted users. Users are encouraged to upgrade to the latest versions to ensure their deployments are secure.

Affected Version(s)

payload < 3.90.0 < 3.90.0

payload >= 4.0.0-canary.0, < 4.0.0-canary.34 < 4.0.0-canary.0, 4.0.0-canary.34

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.