PatchSiren cyber security CVE debrief
CVE-2026-105861 payloadcms CVE debrief
A trust validation issue in Payload's external upload feature could expose authentication data to unintended recipients when external URL-based upload retrieval is enabled and an authenticated request triggers it. This issue affects Payload installations with specific configurations. Users should upgrade to Payload packages >= 3.90.0 or >= 4.0.0-canary.34 to mitigate the vulnerability. The issue arises from the lack of validation for the destination of authentication data during external uploads, potentially leading to unintended exposure of valid sessions.
- Vendor
- payloadcms
- Product
- payload
- CVSS
- HIGH 7.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-07
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-07
- Advisory updated
- 2026-10-07
Who should care
Defenders responsible for Payload installations, particularly those with external URL-based upload retrieval enabled, should assess exposure and prioritize mitigation. This includes reviewing current configurations, verifying affected versions, and applying upgrades or workarounds as needed. Security teams and operators managing Payload deployments should also review the vulnerability's impact on their environments and take appropriate action.
Why it matters
The trust validation issue in Payload's external upload feature could lead to exposure of authentication data. Defenders should prioritize upgrading or applying workarounds, especially if external URL-based upload retrieval is enabled.
- Potential exposure of valid sessions to unintended recipients
- Possible unauthorized access to sensitive data
- Need for verification of affected versions and configurations
- Priority on upgrading or applying workarounds
Technical summary
The trust validation issue in Payload's external upload feature could expose authentication data to unintended recipients. This occurs when external URL-based upload retrieval is enabled and an authenticated request triggers it. The vulnerability stems from insufficient validation of the destination for authentication data during external uploads. Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34. If immediate upgrade is not possible, consider disabling external URL-based upload retrieval or configuring the upload header filter to remove authentication data from outbound file requests.
Defensive priority
Defenders should prioritize upgrading Payload packages to >= 3.90.0 or >= 4.0.0-canary.34. If immediate upgrade is not possible, consider disabling external URL-based upload retrieval or configuring the upload header filter to remove authentication data from outbound file requests.
Recommended defensive actions
- Upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34
- Disable external URL-based upload retrieval where practical
- Configure the upload header filter to remove authentication data from outbound file requests
- Restrict access to the affected upload functionality
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and source item provide details on the trust validation issue in Payload's external upload feature. The issue allows authentication data to be sent to an unverified destination, potentially exposing valid sessions to unintended recipients.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-105861 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-105861
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-105861 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105861
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Payload external upload trust validation issue
Unverified legacy reference
URL: https://storage.googleapis.com/osv-vulnerabilities/npm/GHSA-pj5h-5q6c-3pfx.json
osv_dev
-
Source reference
Unverified legacy reference
URL: https://github.com/payloadcms/payload/security/advisories/GHSA-pj5h-5q6c-3pfx
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/payloadcms/payload/commit/ba5cf6ae20d27a2c15106cb37466419031f86e6d
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/payloadcms/payload
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/payloadcms/payload/releases/tag/v3.90.0
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.