PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-105865 payloadcms CVE debrief

CVE-2026-105865 debrief: Incomplete validation during the upload file lifecycle in Payload could cause unintended file removal, leading to data loss or service disruption. Affected users should upgrade to Payload packages >= 3.90.0 or >= 4.0.0-canary.34. This issue is particularly concerning for users of Payload upload collections with local file storage, especially those with untrusted authenticated users who can update or delete uploads. The vulnerability highlights the importance of validating uploaded filenames and ensuring file cleanup processes are properly contained within configured upload directories.

Vendor
payloadcms
Product
payload
CVSS
HIGH 8.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-07
Original CVE updated
2026-10-07
Advisory published
2026-10-07
Advisory updated
2026-10-07

Who should care

Users of Payload upload collections with local file storage, especially those with untrusted authenticated users who can update or delete uploads, should be aware of this vulnerability. The potential for data loss or service disruption requires immediate attention, particularly for operators managing such systems. Security teams should assess exposure, prioritize remediation, and consider compensating controls until patches can be applied.

Why it matters

CVE-2026-105865 is significant for users of Payload upload collections with local file storage, particularly when untrusted authenticated users can update or delete uploads. The vulnerability could lead to data loss or service disruption. Users should assess exposure, prioritize remediation, and consider compensating controls.

  • Data loss due to unintended file removal
  • Service disruption due to file cleanup issues
  • Need to verify and restrict upload management to trusted users
  • Requirement to validate submitted filenames

Technical summary

Under certain conditions, an authenticated user with permission to modify uploads could cause unintended files to be removed during file cleanup, potentially resulting in data loss or service disruption. This issue arises in Payload upload collections with local file storage when untrusted authenticated users can update or delete uploads. The vulnerability is addressed by validating uploaded filenames and ensuring file cleanup remains within the configured upload directory in Payload packages >= 3.90.0 or >= 4.0.0-canary.34.

Defensive priority

Upgrade to patched versions; restrict upload management to trusted users; validate submitted filenames.

Recommended defensive actions

  • Upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34
  • Restrict upload update and deletion operations to trusted users
  • Validate submitted filenames
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and source item provide details on the vulnerability and patches. Evidence is based on official CVE Program and NIST NVD records, as well as source-specific vulnerability assessments. The CVE record was published on 2026-10-07T20:29:09.000Z and has not been modified since then. The source item from osv_dev also provides relevant information about the vulnerability. However, the impact and mitigation strategies suggest that additional verification may be necessary to ensure complete exposure assessment and remediation.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-105865 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-105865

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-105865 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105865

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Payload: Incomplete validation during the upload file lifecycle

    Unverified legacy reference

    URL: https://storage.googleapis.com/osv-vulnerabilities/npm/GHSA-p223-2wr2-j562.json

    osv_dev

  • Source reference

    Unverified legacy reference

    URL: https://github.com/payloadcms/payload/security/advisories/GHSA-p223-2wr2-j562

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/payloadcms/payload/commit/6b74418f628fa633c2f297e5919a9f91b383dc11

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/payloadcms/payload

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/payloadcms/payload/releases/tag/v3.90.0

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.