Authentication Bypass in Payload CMS Versions Prior to 3.90.0
CVE-2026-105866
6.9MEDIUM
What is CVE-2026-105866?
In certain versions of Payload CMS, an unauthenticated attacker with knowledge of an account's email address or username can exploit a flaw in the account lockout mechanism. This vulnerability allows the attacker to prevent legitimate users from accessing their accounts, disrupting functionality and potentially compromising sensitive information. This issue has been resolved in versions 3.90.0 and above, effectively mitigating the risk associated with this unauthorized access. Users are strongly advised to upgrade to the latest version to protect against such exploits.
Affected Version(s)
payload < 3.90.0 < 3.90.0
payload >= 4.0.0-canary.0, < 4.0.0-canary.34 < 4.0.0-canary.0, 4.0.0-canary.34
