Critical severityNVD Advisory· Published Oct 6, 2026
CVE-2026-105863
CVE-2026-105863
Description
Payload is a free and open source headless content management system. In versions after 3.0.0 and before 3.90.0, a custom field option that maps a field to a reserved authentication claim name can place unintended values in the authentication token issued at login. This issue is fixed in version 3.90.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: >=3.0.0 <3.90.0
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.