CVE-2026-105861
Received
Received - Intake
Authenticated External URL Upload in Payload CMS Session Exposure
Vulnerability report for CVE-2026-105861, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-06
Last updated on: 2026-10-06
Assigner: GitHub, Inc.
Description
Description
Payload is a free and open source headless content management system. In versions after 3.0.0 and before 3.90.0, authenticated external URL-based upload retrieval can forward authentication data to a redirected destination that was not verified as trusted, potentially exposing a valid session to an unintended recipient. This issue is fixed in version 3.90.0.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| payloadcms | payload | > 3.0.0, < 3.90.0 |
| payloadcms | payload | > 4.0.0-canary.0, < 4.0.0-canary-34 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-346 | The product does not properly verify that the source of data or communication is valid. |
| CWE-200 | The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information. |