High severityNVD Advisory· Published Oct 6, 2026· Updated Oct 6, 2026
CVE-2026-105861
CVE-2026-105861
Description
Payload is a free and open source headless content management system. In versions after 3.0.0 and before 3.90.0, authenticated external URL-based upload retrieval can forward authentication data to a redirected destination that was not verified as trusted, potentially exposing a valid session to an unintended recipient. This issue is fixed in version 3.90.0.
Affected products
1- Range: 3.0.0 < 3.90.0
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.