Information Disclosure in PayloadCMS Headless CMS by Payload
CVE-2026-105867
7.1HIGH
What is CVE-2026-105867?
The PayloadCMS, specifically in the @payloadcms/storage-s3 component, has a vulnerability that allows authenticated users to overwrite existing S3 objects from other collections due to improper access control configurations. This flaw occurs when multiple collections share a single S3 bucket and the useCompositePrefixes option is set to false or is unset, thereby bypassing the intended access restrictions and file validation processes. The issue has been addressed in subsequent releases, providing users an essential update to secure their systems.
Affected Version(s)
payload < 3.90.0 < 3.90.0
payload >= 4.0.0-canary.0, < 4.0.0-canary.34 < 4.0.0-canary.0, 4.0.0-canary.34
storage-s3 < 3.90.0 < 3.90.0
