Vulnerability
Published 2026-10-06
Verified 2026-10-07

Payload CMS: at least 29 CVEs published on 6 October, including unauthenticated RCE in the Form Builder plugin (CVE-2026-105857, CVSS 10.0), SQL injection (CVE-2026-105845, 9.8) and RCE through first-register; fixes in 3.88.0 and 3.90.0

Payload, the open-source TypeScript headless CMS and application framework, had at least 29 CVEs published through GitHub's CNA on 6 October 2026 across the core package and official plugins. The worst: CVE-2026-105857 (CVSS 3.1 10.0), a crafted form submission that runs code on the server when @payloadcms/plugin-form-builder is used, fixed in 3.90.0; CVE-2026-105845 (9.8), SQL injection in the SQLite and Postgres adapters by anyone who can query readable collections with dynamic filters or joins, fixed in 3.88.0; CVE-2026-105844 (CVSS 4.0 9.3), prototype pollution through @payloadcms/plugin-import-export by an unauthenticated user that can lead to code execution, fixed in 3.88.0; CVE-2026-105863 (9.2), custom fields mapped to reserved authentication claim names placing attacker-chosen values in login tokens, fixed in 3.90.0; and CVE-2026-105858 (8.1), remote code execution through the public first-register operation on an instance with local authentication and no first user yet. Others include a second SQL injection through json or blocks fields (CVE-2026-105856, 8.6), API keys readable through ordinary document reads (CVE-2026-105849), MCP API key management outside the caller's own account in @payloadcms/plugin-mcp 3.61.0 to 3.87.x (CVE-2026-105806, 8.6), multi-tenant plugin isolation bypasses, password field access-control bypass, S3 object overwrite, Stripe proxy misuse, path traversal in local upload cleanup, and a PBKDF2 work factor below current guidance. The 4.0 canary line is fixed in 4.0.0-canary.34. No exploitation has been reported. Primary: Payload GitHub security advisories and CVE records.

Product
Payload CMS (payload and @payloadcms/* packages, including plugin-form-builder, plugin-import-export, plugin-mcp, plugin-multi-tenant, plugin-stripe, storage-s3, db-mongodb)
Versions
3.x before 3.90.0 (some issues before 3.88.0); 4.0.0 canary before 4.0.0-canary.34. Fixed in 3.90.0 and 4.0.0-canary.34.
CVSS
Critical (CVE-2026-105857, CVSS 3.1); 9.8 (CVE-2026-105845); 9.3 and 9.2 (CVE-2026-105844 and 105863, CVSS 4.0)
Exploited in Australia?
unknown
Patch to
Upgrade payload and every @payloadcms/* package together to 3.90.0 or later (canary users to 4.0.0-canary.34). If you cannot upgrade at once, disable public form submissions and the import-export and MCP plugins, make sure the first administrator account already exists on every instance, and keep the admin and API endpoints behind access controls. After upgrading, rotate API keys and review accounts, tenants and uploads for changes you did not make.

Primary: Payload — GHSA-r488-j9vj-wx3q: RCE in Payload Form Builder (CVE-2026-105857) · Vendor: Payload — v3.90.0 release · CVE: CVE-2026-105857, CVE-2026-105845, CVE-2026-105844, CVE-2026-105863, CVE-2026-105858, CVE-2026-105856, CVE-2026-105849, CVE-2026-105806 · Payload — all GitHub security advisories

tech cloud