PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-105857 payloadcms CVE debrief

A vulnerability in `@payloadcms/plugin-form-builder` versions less than 3.90.0 allows submissions that could be crafted to execute remote code on the server. This issue arises from improper handling of user input, potentially leading to unauthorized code execution. Users of `@payloadcms/plugin-form-builder` should upgrade to version 3.90.0 or later, or 4.0.0-canary.34 or later, and verify the upgrade to prevent exploitation. It's crucial for defenders to prioritize patching and ensure version upgrades are correctly implemented.

Vendor
payloadcms
Product
@payloadcms/plugin-form-builder
CVSS
CRITICAL 10
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-07
Original CVE updated
2026-10-07
Advisory published
2026-10-07
Advisory updated
2026-10-07

Who should care

Users of `@payloadcms/plugin-form-builder` versions less than 3.90.0 should be aware of this vulnerability and take steps to upgrade to a patched version. This includes operators, platform administrators, vulnerability management teams, and security teams who need to ensure that affected systems are updated and verified to prevent exploitation. Prioritizing patching and verifying version upgrades are crucial steps in mitigating the risk associated with CVE

Why it matters

CVE-2026-105857 is a remote code execution vulnerability in `@payloadcms/plugin-form-builder` versions less than 3.90.0. Users should upgrade to version 3.90.0 or later, or 4.0.0-canary.34 or later. Defenders should prioritize patching and verify version upgrades to prevent exploitation.

  • Remote code execution can lead to unauthorized access and control of the server.
  • Successful exploitation can result in data breaches and unauthorized modifications.
  • Defenders should prioritize upgrading `@payloadcms/plugin-form-builder` to a patched version.
  • Verification of version upgrades is necessary to ensure patching.

Technical summary

The vulnerability in `@payloadcms/plugin-form-builder` versions less than 3.90.0 allows submissions that could be crafted to execute remote code on the server. This is due to improper handling of user input, which can lead to remote code execution. The issue is addressed in versions 3.90.0 and 4.0.0-canary.34 or later. Users should upgrade to a patched version and verify the upgrade to prevent exploitation. The vulnerability highlights the importance of secure input handling and timely software updates. Defenders should prioritize patching and ensure that version upgrades are correctly implemented to mitigate the risk of remote code execution.

Defensive priority

Upgrade `@payloadcms/plugin-form-builder` to version 3.90.0 or later, or 4.0.0-canary.34 or later.

Recommended defensive actions

  • Upgrade `@payloadcms/plugin-form-builder` to version 3.90.0 or later
  • Upgrade `@payloadcms/plugin-form-builder` to version 4.0.0-canary.34 or later
  • Review and update affected systems
  • Verify version upgrades
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The vulnerability is described in the source item from osv_dev, which mentions that submissions can be crafted to execute remote code on the server. The CVE Program record and NVD vulnerability detail pages provide additional context.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-105857 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-105857

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-105857 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105857

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Payload Form Builder has an RCE issue

    Unverified legacy reference

    URL: https://storage.googleapis.com/osv-vulnerabilities/npm/GHSA-r488-j9vj-wx3q.json

    osv_dev

  • Source reference

    Unverified legacy reference

    URL: https://github.com/payloadcms/payload/security/advisories/GHSA-r488-j9vj-wx3q

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/payloadcms/payload/commit/333b82b9f3e685fed6826c2e3270da79df8336c6

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/payloadcms/payload

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/payloadcms/payload/releases/tag/v3.90.0

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.