PatchSiren cyber security CVE debrief
CVE-2026-105865 payloadcms CVE debrief
CVE-2026-105865 debrief: Incomplete validation during the upload file lifecycle in Payload could cause unintended file removal, leading to data loss or service disruption. Affected users should upgrade to Payload packages >= 3.90.0 or >= 4.0.0-canary.34. This issue is particularly concerning for users of Payload upload collections with local file storage, especially those with untrusted authenticated users who can update or delete uploads. The vulnerability highlights the importance of validating uploaded filenames and ensuring file cleanup processes are properly contained within configured upload directories.
- Vendor
- payloadcms
- Product
- payload
- CVSS
- HIGH 8.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-07
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-07
- Advisory updated
- 2026-10-07
Who should care
Users of Payload upload collections with local file storage, especially those with untrusted authenticated users who can update or delete uploads, should be aware of this vulnerability. The potential for data loss or service disruption requires immediate attention, particularly for operators managing such systems. Security teams should assess exposure, prioritize remediation, and consider compensating controls until patches can be applied.
Why it matters
CVE-2026-105865 is significant for users of Payload upload collections with local file storage, particularly when untrusted authenticated users can update or delete uploads. The vulnerability could lead to data loss or service disruption. Users should assess exposure, prioritize remediation, and consider compensating controls.
- Data loss due to unintended file removal
- Service disruption due to file cleanup issues
- Need to verify and restrict upload management to trusted users
- Requirement to validate submitted filenames
Technical summary
Under certain conditions, an authenticated user with permission to modify uploads could cause unintended files to be removed during file cleanup, potentially resulting in data loss or service disruption. This issue arises in Payload upload collections with local file storage when untrusted authenticated users can update or delete uploads. The vulnerability is addressed by validating uploaded filenames and ensuring file cleanup remains within the configured upload directory in Payload packages >= 3.90.0 or >= 4.0.0-canary.34.
Defensive priority
Upgrade to patched versions; restrict upload management to trusted users; validate submitted filenames.
Recommended defensive actions
- Upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34
- Restrict upload update and deletion operations to trusted users
- Validate submitted filenames
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and source item provide details on the vulnerability and patches. Evidence is based on official CVE Program and NIST NVD records, as well as source-specific vulnerability assessments. The CVE record was published on 2026-10-07T20:29:09.000Z and has not been modified since then. The source item from osv_dev also provides relevant information about the vulnerability. However, the impact and mitigation strategies suggest that additional verification may be necessary to ensure complete exposure assessment and remediation.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-105865 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-105865
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-105865 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105865
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Payload: Incomplete validation during the upload file lifecycle
Unverified legacy reference
URL: https://storage.googleapis.com/osv-vulnerabilities/npm/GHSA-p223-2wr2-j562.json
osv_dev
-
Source reference
Unverified legacy reference
URL: https://github.com/payloadcms/payload/security/advisories/GHSA-p223-2wr2-j562
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/payloadcms/payload/commit/6b74418f628fa633c2f297e5919a9f91b383dc11
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/payloadcms/payload
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/payloadcms/payload/releases/tag/v3.90.0
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.