PatchSiren cyber security CVE debrief
CVE-2026-105857 payloadcms CVE debrief
A vulnerability in `@payloadcms/plugin-form-builder` versions less than 3.90.0 allows submissions that could be crafted to execute remote code on the server. This issue arises from improper handling of user input, potentially leading to unauthorized code execution. Users of `@payloadcms/plugin-form-builder` should upgrade to version 3.90.0 or later, or 4.0.0-canary.34 or later, and verify the upgrade to prevent exploitation. It's crucial for defenders to prioritize patching and ensure version upgrades are correctly implemented.
- Vendor
- payloadcms
- Product
- @payloadcms/plugin-form-builder
- CVSS
- CRITICAL 10
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-07
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-07
- Advisory updated
- 2026-10-07
Who should care
Users of `@payloadcms/plugin-form-builder` versions less than 3.90.0 should be aware of this vulnerability and take steps to upgrade to a patched version. This includes operators, platform administrators, vulnerability management teams, and security teams who need to ensure that affected systems are updated and verified to prevent exploitation. Prioritizing patching and verifying version upgrades are crucial steps in mitigating the risk associated with CVE
Why it matters
CVE-2026-105857 is a remote code execution vulnerability in `@payloadcms/plugin-form-builder` versions less than 3.90.0. Users should upgrade to version 3.90.0 or later, or 4.0.0-canary.34 or later. Defenders should prioritize patching and verify version upgrades to prevent exploitation.
- Remote code execution can lead to unauthorized access and control of the server.
- Successful exploitation can result in data breaches and unauthorized modifications.
- Defenders should prioritize upgrading `@payloadcms/plugin-form-builder` to a patched version.
- Verification of version upgrades is necessary to ensure patching.
Technical summary
The vulnerability in `@payloadcms/plugin-form-builder` versions less than 3.90.0 allows submissions that could be crafted to execute remote code on the server. This is due to improper handling of user input, which can lead to remote code execution. The issue is addressed in versions 3.90.0 and 4.0.0-canary.34 or later. Users should upgrade to a patched version and verify the upgrade to prevent exploitation. The vulnerability highlights the importance of secure input handling and timely software updates. Defenders should prioritize patching and ensure that version upgrades are correctly implemented to mitigate the risk of remote code execution.
Defensive priority
Upgrade `@payloadcms/plugin-form-builder` to version 3.90.0 or later, or 4.0.0-canary.34 or later.
Recommended defensive actions
- Upgrade `@payloadcms/plugin-form-builder` to version 3.90.0 or later
- Upgrade `@payloadcms/plugin-form-builder` to version 4.0.0-canary.34 or later
- Review and update affected systems
- Verify version upgrades
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The vulnerability is described in the source item from osv_dev, which mentions that submissions can be crafted to execute remote code on the server. The CVE Program record and NVD vulnerability detail pages provide additional context.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-105857 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-105857
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-105857 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105857
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Payload Form Builder has an RCE issue
Unverified legacy reference
URL: https://storage.googleapis.com/osv-vulnerabilities/npm/GHSA-r488-j9vj-wx3q.json
osv_dev
-
Source reference
Unverified legacy reference
URL: https://github.com/payloadcms/payload/security/advisories/GHSA-r488-j9vj-wx3q
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/payloadcms/payload/commit/333b82b9f3e685fed6826c2e3270da79df8336c6
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/payloadcms/payload
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/payloadcms/payload/releases/tag/v3.90.0
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.