PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-105858 payloadcms CVE debrief

A crafted request to the public first-register operation can be used to perform a RCE exploit in Payload packages. Users of local auth strategy without an initial user created are affected. Patches are available in Payload packages >= 3.90.0 or >= 4.0.0-canary.34. This vulnerability allows attackers to execute arbitrary code, potentially leading to significant operational impact. Defenders should assess exposure and prioritize upgrading to >= 3.90.0 or >= 4.0.0-canary.34. The vulnerability is due to improper sanitization of data submission to create the first user.

Vendor
payloadcms
Product
payload
CVSS
HIGH 8.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-07
Original CVE updated
2026-10-07
Advisory published
2026-10-07
Advisory updated
2026-10-07

Who should care

Defenders of systems using Payload packages with local auth strategy and without an initial user created should assess exposure and prioritize upgrading to >= 3.90.0 or >= 4.0.0-canary.34.

Why it matters

CVE-2026-105858 is a Remote Code Execution vulnerability in Payload packages that can be exploited through a crafted request to the public first-register operation. Defenders should prioritize upgrading Payload packages and verify if their application is vulnerable.

  • Verify if the application is vulnerable due to local auth strategy and lack of initial user creation
  • Upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34 to prevent potential RCE exploits
  • Monitor for potential exploitation attempts

Technical summary

A crafted request to the public first-register operation can be used to perform a RCE exploit in Payload packages. This is due to improper sanitization of data submission to create the first user. Users of local auth strategy without an initial user created are affected. The vulnerability allows for arbitrary code execution, which can lead to significant operational impacts. Defenders should prioritize upgrading Payload packages to >= 3.90.0 or >= 4.0.0-canary.34 and verify if their application is vulnerable due to the local auth strategy and lack of initial user creation.

Defensive priority

Defenders should prioritize upgrading Payload packages to >= 3.90.0 or >= 4.0.0-canary.34 and verify if their application is vulnerable due to the local auth strategy and lack of initial user creation.

Recommended defensive actions

  • Upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34
  • Verify if the application is vulnerable due to local auth strategy and lack of initial user creation
  • Monitor for potential exploitation attempts
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The source corpus provides details on the vulnerability and patches but does not confirm exploitation or specific victims. Evidence is limited to source-provided information. There is no information on known or unknown affected scope beyond the provided source details. Defenders should verify if their application is vulnerable due to local auth strategy and lack of initial user creation.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-105858 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-105858

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-105858 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105858

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Payload: Remote Code Execution through first-register

    Unverified legacy reference

    URL: https://storage.googleapis.com/osv-vulnerabilities/npm/GHSA-97rh-rhh2-7vjv.json

    osv_dev

  • Source reference

    Unverified legacy reference

    URL: https://github.com/payloadcms/payload/security/advisories/GHSA-97rh-rhh2-7vjv

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/payloadcms/payload/commit/e947fc4ba4a434f276d043386e501b1d14eda679

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/payloadcms/payload

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/payloadcms/payload/releases/tag/v3.90.0

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.