Information Disclosure in PayloadCMS Headless CMS by Payload
CVE-2026-105867

7.1HIGH

Key Information:

Vendor

Payloadcms

Vendor
CVE Published:
6 October 2026

What is CVE-2026-105867?

The PayloadCMS, specifically in the @payloadcms/storage-s3 component, has a vulnerability that allows authenticated users to overwrite existing S3 objects from other collections due to improper access control configurations. This flaw occurs when multiple collections share a single S3 bucket and the useCompositePrefixes option is set to false or is unset, thereby bypassing the intended access restrictions and file validation processes. The issue has been addressed in subsequent releases, providing users an essential update to secure their systems.

Affected Version(s)

payload < 3.90.0 < 3.90.0

payload >= 4.0.0-canary.0, < 4.0.0-canary.34 < 4.0.0-canary.0, 4.0.0-canary.34

storage-s3 < 3.90.0 < 3.90.0

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.