PatchSiren cyber security CVE debrief
CVE-2026-105858 payloadcms CVE debrief
A crafted request to the public first-register operation can be used to perform a RCE exploit in Payload packages. Users of local auth strategy without an initial user created are affected. Patches are available in Payload packages >= 3.90.0 or >= 4.0.0-canary.34. This vulnerability allows attackers to execute arbitrary code, potentially leading to significant operational impact. Defenders should assess exposure and prioritize upgrading to >= 3.90.0 or >= 4.0.0-canary.34. The vulnerability is due to improper sanitization of data submission to create the first user.
- Vendor
- payloadcms
- Product
- payload
- CVSS
- HIGH 8.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-07
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-07
- Advisory updated
- 2026-10-07
Who should care
Defenders of systems using Payload packages with local auth strategy and without an initial user created should assess exposure and prioritize upgrading to >= 3.90.0 or >= 4.0.0-canary.34.
Why it matters
CVE-2026-105858 is a Remote Code Execution vulnerability in Payload packages that can be exploited through a crafted request to the public first-register operation. Defenders should prioritize upgrading Payload packages and verify if their application is vulnerable.
- Verify if the application is vulnerable due to local auth strategy and lack of initial user creation
- Upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34 to prevent potential RCE exploits
- Monitor for potential exploitation attempts
Technical summary
A crafted request to the public first-register operation can be used to perform a RCE exploit in Payload packages. This is due to improper sanitization of data submission to create the first user. Users of local auth strategy without an initial user created are affected. The vulnerability allows for arbitrary code execution, which can lead to significant operational impacts. Defenders should prioritize upgrading Payload packages to >= 3.90.0 or >= 4.0.0-canary.34 and verify if their application is vulnerable due to the local auth strategy and lack of initial user creation.
Defensive priority
Defenders should prioritize upgrading Payload packages to >= 3.90.0 or >= 4.0.0-canary.34 and verify if their application is vulnerable due to the local auth strategy and lack of initial user creation.
Recommended defensive actions
- Upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34
- Verify if the application is vulnerable due to local auth strategy and lack of initial user creation
- Monitor for potential exploitation attempts
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The source corpus provides details on the vulnerability and patches but does not confirm exploitation or specific victims. Evidence is limited to source-provided information. There is no information on known or unknown affected scope beyond the provided source details. Defenders should verify if their application is vulnerable due to local auth strategy and lack of initial user creation.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-105858 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-105858
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-105858 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105858
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Payload: Remote Code Execution through first-register
Unverified legacy reference
URL: https://storage.googleapis.com/osv-vulnerabilities/npm/GHSA-97rh-rhh2-7vjv.json
osv_dev
-
Source reference
Unverified legacy reference
URL: https://github.com/payloadcms/payload/security/advisories/GHSA-97rh-rhh2-7vjv
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/payloadcms/payload/commit/e947fc4ba4a434f276d043386e501b1d14eda679
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/payloadcms/payload
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/payloadcms/payload/releases/tag/v3.90.0
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.