PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-105861 payloadcms CVE debrief

A trust validation issue in Payload's external upload feature could expose authentication data to unintended recipients when external URL-based upload retrieval is enabled and an authenticated request triggers it. This issue affects Payload installations with specific configurations. Users should upgrade to Payload packages >= 3.90.0 or >= 4.0.0-canary.34 to mitigate the vulnerability. The issue arises from the lack of validation for the destination of authentication data during external uploads, potentially leading to unintended exposure of valid sessions.

Vendor
payloadcms
Product
payload
CVSS
HIGH 7.2
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-07
Original CVE updated
2026-10-07
Advisory published
2026-10-07
Advisory updated
2026-10-07

Who should care

Defenders responsible for Payload installations, particularly those with external URL-based upload retrieval enabled, should assess exposure and prioritize mitigation. This includes reviewing current configurations, verifying affected versions, and applying upgrades or workarounds as needed. Security teams and operators managing Payload deployments should also review the vulnerability's impact on their environments and take appropriate action.

Why it matters

The trust validation issue in Payload's external upload feature could lead to exposure of authentication data. Defenders should prioritize upgrading or applying workarounds, especially if external URL-based upload retrieval is enabled.

  • Potential exposure of valid sessions to unintended recipients
  • Possible unauthorized access to sensitive data
  • Need for verification of affected versions and configurations
  • Priority on upgrading or applying workarounds

Technical summary

The trust validation issue in Payload's external upload feature could expose authentication data to unintended recipients. This occurs when external URL-based upload retrieval is enabled and an authenticated request triggers it. The vulnerability stems from insufficient validation of the destination for authentication data during external uploads. Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34. If immediate upgrade is not possible, consider disabling external URL-based upload retrieval or configuring the upload header filter to remove authentication data from outbound file requests.

Defensive priority

Defenders should prioritize upgrading Payload packages to >= 3.90.0 or >= 4.0.0-canary.34. If immediate upgrade is not possible, consider disabling external URL-based upload retrieval or configuring the upload header filter to remove authentication data from outbound file requests.

Recommended defensive actions

  • Upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34
  • Disable external URL-based upload retrieval where practical
  • Configure the upload header filter to remove authentication data from outbound file requests
  • Restrict access to the affected upload functionality
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and source item provide details on the trust validation issue in Payload's external upload feature. The issue allows authentication data to be sent to an unverified destination, potentially exposing valid sessions to unintended recipients.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-105861 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-105861

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-105861 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105861

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Payload external upload trust validation issue

    Unverified legacy reference

    URL: https://storage.googleapis.com/osv-vulnerabilities/npm/GHSA-pj5h-5q6c-3pfx.json

    osv_dev

  • Source reference

    Unverified legacy reference

    URL: https://github.com/payloadcms/payload/security/advisories/GHSA-pj5h-5q6c-3pfx

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/payloadcms/payload/commit/ba5cf6ae20d27a2c15106cb37466419031f86e6d

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/payloadcms/payload

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/payloadcms/payload/releases/tag/v3.90.0

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.