CVE-2026-105846
Received Received - Intake

Open Redirect Vulnerability in Payload CMS

Vulnerability report for CVE-2026-105846, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: GitHub, Inc.

Description

Payload is a free and open source headless content management system. In versions from 3.40.0 before 3.88.0 and canary versions before 4.0.0-canary.27, an attacker can craft a redirect URL parameter that sends a guest user to an untrusted destination after the authentication flow completes. This issue is fixed in versions 3.88.0 and 4.0.0-canary.27.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
payloadcms payload >= 3.40.0, < 3.88.0
payloadcms payload >= 4.0.0-canary.0, < 4.0.0-canary.27
@payloadcms next >= 3.31.0, < 3.88.0
@payloadcms next >= 4.0.0-canary.0, < 4.0.0-canary.27

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-601 The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Payload CMS versions from 3.40.0 before 3.88.0 and canary versions before 4.0.0-canary.27 have an open redirect vulnerability. An attacker can craft a URL parameter that redirects a guest user to an untrusted destination after they complete the authentication process.

Detection Guidance

Check Payload CMS version with: npm list @payloadcms/next or npm list payload. If version is between 3.40.0 and 3.88.0 or canary before 4.0.0-canary.27, it is vulnerable. Inspect network traffic for unusual redirect URLs after authentication flows.

Impact Analysis

This vulnerability could allow attackers to trick users into visiting malicious websites after login, potentially leading to phishing attacks, credential theft, or malware infections. Users may unknowingly expose sensitive data or system access.

Compliance Impact

The vulnerability allows an attacker to redirect users to untrusted destinations after authentication, which could lead to phishing attacks or unauthorized data exposure. This may violate GDPR's requirement for secure user authentication and data protection, and HIPAA's safeguards for protecting sensitive health information during access.

Mitigation Strategies

Upgrade Payload CMS to version 3.88.0 or 4.0.0-canary.27 or later immediately. Review and restrict redirect URL parameters in authentication flows. Monitor for suspicious redirects or unauthorized access attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105846. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart