Authentication Bypass in Payload CMS Versions Prior to 3.90.0
CVE-2026-105866

6.9MEDIUM

Key Information:

Vendor

Payloadcms

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-105866?

In certain versions of Payload CMS, an unauthenticated attacker with knowledge of an account's email address or username can exploit a flaw in the account lockout mechanism. This vulnerability allows the attacker to prevent legitimate users from accessing their accounts, disrupting functionality and potentially compromising sensitive information. This issue has been resolved in versions 3.90.0 and above, effectively mitigating the risk associated with this unauthorized access. Users are strongly advised to upgrade to the latest version to protect against such exploits.

Affected Version(s)

payload < 3.90.0 < 3.90.0

payload >= 4.0.0-canary.0, < 4.0.0-canary.34 < 4.0.0-canary.0, 4.0.0-canary.34

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.