PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-105866 payloadcms CVE debrief

CVE-2026-105866 debrief: Unauthenticated account-lockout denial of service in Payload. Upgrade to >= 3.90.0 or >= 4.0.0-canary.34. This vulnerability allows an unauthenticated attacker to trigger account lockout, potentially disrupting service and increasing help desk requests. Defenders should assess exposure and prioritize upgrading to the latest versions. The vulnerability affects Payload versions with auth-enabled collections using local authentication and account lockout. Successful password resets now clear the account's lockout state, and the forgot-password flow enforces a configurable minimum interval between reset emails.

Vendor
payloadcms
Product
payload
CVSS
MEDIUM 6.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-07
Original CVE updated
2026-10-07
Advisory published
2026-10-07
Advisory updated
2026-10-07

Who should care

Defenders responsible for Payload installations, particularly those using local authentication and account lockout, should assess exposure and prioritize upgrading to >= 3.90.0 or >= 4.0.0-canary.34. This includes operators, platform administrators, vulnerability management teams, and security teams who need to verify affected versions and exposure, and plan for upgrades and patches.

Why it matters

CVE-2026-105866 is a denial of service vulnerability in Payload that can be triggered by an unauthenticated attacker, potentially leading to service disruption and increased help desk requests. Defenders should prioritize upgrading to >= 3.90.0 or >= 4.0.0-canary.34 and verify affected versions and exposure.

  • Denial of service for legitimate users
  • Potential for increased help desk requests
  • Need for verification of affected versions and exposure
  • Prioritization of upgrades and patches

Technical summary

An unauthenticated attacker who knows an account's email address or username could trigger Payload's account lockout mechanism and prevent that user from signing in. You are affected if using an affected Payload version with an auth-enabled collection that uses local authentication and account lockout. Successful password resets now clear the account's lockout state, and the forgot-password flow enforces a configurable minimum interval between reset emails. Defenders should assess exposure and prioritize upgrading to >= 3.90.0 or >= 4.0.0-canary.34.

Defensive priority

Defenders should prioritize upgrading Payload packages to >= 3.90.0 or >= 4.0.0-canary.34 to prevent unauthenticated account-lockout denial of service.

Recommended defensive actions

  • Upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34
  • Review and update auth-enabled collections that use local authentication and account lockout
  • Monitor for potential denial of service attacks
  • Verify affected Payload versions and exposure
  • Prioritize upgrades and patches for affected deployments
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and source item provide details on the vulnerability, including the impact, patches, and affected versions. The vulnerability was publicly disclosed on 2026-10-07T20:29:04.000Z. Defenders should verify affected Payload versions and upgrade to >= 3.90.0 or >= 4.0.0-canary.34. The source item and CVE record do not provide additional information on exploitability or affected deployments.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-105866 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-105866

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-105866 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105866

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Payload: Unauthenticated account-lockout denial of service

    Unverified legacy reference

    URL: https://storage.googleapis.com/osv-vulnerabilities/npm/GHSA-v5gf-vpjc-pc7w.json

    osv_dev

  • Source reference

    Unverified legacy reference

    URL: https://github.com/payloadcms/payload/security/advisories/GHSA-v5gf-vpjc-pc7w

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/payloadcms/payload/commit/1c46204a73a0a9f988a80c52690eee5a4ada3cf1

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/payloadcms/payload

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/payloadcms/payload/releases/tag/v3.90.0

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.