CRITICAL 9.8 CVE-2026-105859 Published 6 Oct 2026

Payload CMS Access Control Bypass in Update Endpoint

Worried this affects your website?

Payload, a free and open source headless content management system, has an access control bypass vulnerability in its update endpoint.

An attacker can submit a request to a specific update endpoint that modifies collection documents without enforcing collection or field-level access control.

  • Affects versions before 3.90.0 and canary versions before 4.0.0-canary.34.
  • Requires orderable to be enabled on a collection or join field.
  • Fixed in versions 3.90.0 and 4.0.0-canary.34.

Reference: CVE-2026-105859 on NVD

← Back to Security News