VYPR
advisoryPublished Oct 6, 2026· Updated Oct 8, 2026· 1 source

Payload CMS: 25 Vulnerabilities Disclosed in Single Batch, Including RCE and SQLi

Key findings • Critical vulnerabilities in Payload CMS allow for remote code execution and SQL injection. • Multiple high-severity flaws enable unauthorized data modification and file overwri…

Key findings

  • Critical vulnerabilities in Payload CMS allow for remote code execution and SQL injection.
  • Multiple high-severity flaws enable unauthorized data modification and file overwrites.
  • Access control bypasses affect field-level permissions and document updates.
  • File upload vulnerabilities can lead to JavaScript execution and data loss.
  • Issues in multi-tenancy and Stripe integrations impact core functionalities.
  • All disclosed vulnerabilities are fixed in Payload CMS versions 3.90.0 and 4.0.0-canary.34.

On October 6, 2026, a significant batch of 25 vulnerabilities was disclosed for Payload CMS, a popular open-source headless content management system. These vulnerabilities, disclosed within a one-hour window, span a range of severities, including critical and high-risk flaws, impacting various components and functionalities of the CMS. The disclosures highlight potential risks in areas such as data handling, authentication, file uploads, and multi-tenancy configurations.

Several vulnerabilities revolve around improper access control and data manipulation. CVE-2026-106100 and CVE-2026-105859, for instance, detail how authenticated users could bypass field-level write access controls to modify restricted fields or collection documents. Similarly, CVE-2026-105855 indicates a failure to enforce update restrictions on the password field, while CVE-2026-105851 describes an issue where the duplicate operation copies values from a source document without respecting access controls.

File upload functionalities are also implicated in multiple disclosures. CVE-2026-105862 points to a critical vulnerability where malicious SVG uploads could bypass sanitization and execute JavaScript. CVE-2026-105865 describes how authenticated users could overwrite unintended files in local storage, leading to data loss. Furthermore, CVE-2026-105868 highlights a risk where local upload configurations accepting XML files could lead to JavaScript execution when a logged-in user opens the file. CVE-2026-105853 and CVE-2026-105847 detail how polymorphic joins and token refresh/password reset responses could expose sensitive or restricted fields.

Authentication and authorization mechanisms were also targeted. CVE-2026-105863, a critical vulnerability, allows unintended values to be placed in authentication tokens due to custom field options mapping to reserved claim names. CVE-2026-105856 describes an SQL injection vulnerability in collections with JSON or blocksAsJSON enabled fields, exploitable by attackers with read and create/update access. CVE-2026-105854 details a denial-of-service vulnerability caused by malformed multipart request bodies. CVE-2026-105866 addresses an account lockout abuse mechanism that could prevent legitimate account access. CVE-2026-105849 allows users with ordinary read access to obtain active API keys from other authentication documents.

The multi-tenant plugin and e-commerce functionalities were not spared. CVE-2026-105864 and CVE-2026-105860 highlight issues within the multi-tenant plugin, allowing authenticated users to create records in other tenants or assign their accounts to different tenants. CVE-2026-105820 and CVE-2026-105848 point to vulnerabilities in the Stripe integration, including potential double processing of orders and unintended Stripe operations via the REST proxy.

Finally, CVE-2026-105858 describes a remote code execution vulnerability in the public first-register operation when local authentication is enabled and no initial user exists. CVE-2026-105845, another critical vulnerability, allows SQL injection in SQLite and Postgres adapters through dynamic filters or joins. CVE-2026-105846 presents a risk of redirecting guest users to untrusted destinations after authentication.

All these vulnerabilities were addressed in Payload CMS versions 3.90.0 and 4.0.0-canary.34, with specific versions noted for certain CVEs. Users are strongly advised to update to the patched versions to mitigate these security risks. The sheer volume and severity of these disclosures underscore the importance of diligent security practices and timely updates for Payload CMS deployments.

The disclosures collectively indicate a need for thorough security audits of access control, file handling, authentication, and plugin integrations within Payload CMS. Users should prioritize updating their instances to the latest secure versions to protect against these widespread vulnerabilities.

Key findings include:

  • Critical vulnerabilities in Payload CMS allow for remote code execution and SQL injection.
  • Multiple high-severity flaws enable unauthorized data modification and file overwrites.
  • Access control bypasses affect field-level permissions and document updates.
  • File upload vulnerabilities can lead to JavaScript execution and data loss.
  • Issues in multi-tenancy and Stripe integrations impact core functionalities.
  • All disclosed vulnerabilities are fixed in Payload CMS versions 3.90.0 and 4.0.0-canary.34.

CVE IDs: ['CVE-2026-106100', 'CVE-2026-105868', 'CVE-2026-105867', 'CVE-2026-105866', 'CVE-2026-105865', 'CVE-2026-105864', 'CVE-2026-105863', 'CVE-2026-105862', 'CVE-2026-105861', 'CVE-2026-105860', 'CVE-2026-105859', 'CVE-2026-105858', 'CVE-2026-105857', 'CVE-2026-105856', 'CVE-2026-105855', 'CVE-2026-105854', 'CVE-2026-105853', 'CVE-2026-105852', 'CVE-2026-105851', 'CVE-2026-105850', 'CVE-2026-105849', 'CVE-2026-105848', 'CVE-2026-105847', 'CVE-2026-105846', 'CVE-2026-105845'] Image prompt: A stylized representation of a Payload CMS backend interface, with various security icons like shields and locks being breached by abstract code-like tendrils. The overall color scheme should be dark with glowing accents. Title: Payload CMS: 25 Vulnerabilities Disclosed in Single Batch, Including RCE and SQLi Lede: A batch of 25 vulnerabilities, including critical RCE and SQLi flaws, were disclosed for Payload CMS, impacting versions prior to 3.90.0 and 4.0.0-canary.34.

Synthesized by Vypr AI