CRITICAL
9.8 CVE-2026-105859 Published 6 Oct 2026
Payload CMS Access Control Bypass in Update Endpoint
Worried this affects your website?
Payload, a free and open source headless content management system, has an access control bypass vulnerability in its update endpoint.
An attacker can submit a request to a specific update endpoint that modifies collection documents without enforcing collection or field-level access control.
- Affects versions before 3.90.0 and canary versions before 4.0.0-canary.34.
- Requires orderable to be enabled on a collection or join field.
- Fixed in versions 3.90.0 and 4.0.0-canary.34.
Reference: CVE-2026-105859 on NVD
← Back to Security News