PatchSiren cyber security CVE debrief
CVE-2026-105866 payloadcms CVE debrief
CVE-2026-105866 debrief: Unauthenticated account-lockout denial of service in Payload. Upgrade to >= 3.90.0 or >= 4.0.0-canary.34. This vulnerability allows an unauthenticated attacker to trigger account lockout, potentially disrupting service and increasing help desk requests. Defenders should assess exposure and prioritize upgrading to the latest versions. The vulnerability affects Payload versions with auth-enabled collections using local authentication and account lockout. Successful password resets now clear the account's lockout state, and the forgot-password flow enforces a configurable minimum interval between reset emails.
- Vendor
- payloadcms
- Product
- payload
- CVSS
- MEDIUM 6.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-07
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-07
- Advisory updated
- 2026-10-07
Who should care
Defenders responsible for Payload installations, particularly those using local authentication and account lockout, should assess exposure and prioritize upgrading to >= 3.90.0 or >= 4.0.0-canary.34. This includes operators, platform administrators, vulnerability management teams, and security teams who need to verify affected versions and exposure, and plan for upgrades and patches.
Why it matters
CVE-2026-105866 is a denial of service vulnerability in Payload that can be triggered by an unauthenticated attacker, potentially leading to service disruption and increased help desk requests. Defenders should prioritize upgrading to >= 3.90.0 or >= 4.0.0-canary.34 and verify affected versions and exposure.
- Denial of service for legitimate users
- Potential for increased help desk requests
- Need for verification of affected versions and exposure
- Prioritization of upgrades and patches
Technical summary
An unauthenticated attacker who knows an account's email address or username could trigger Payload's account lockout mechanism and prevent that user from signing in. You are affected if using an affected Payload version with an auth-enabled collection that uses local authentication and account lockout. Successful password resets now clear the account's lockout state, and the forgot-password flow enforces a configurable minimum interval between reset emails. Defenders should assess exposure and prioritize upgrading to >= 3.90.0 or >= 4.0.0-canary.34.
Defensive priority
Defenders should prioritize upgrading Payload packages to >= 3.90.0 or >= 4.0.0-canary.34 to prevent unauthenticated account-lockout denial of service.
Recommended defensive actions
- Upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34
- Review and update auth-enabled collections that use local authentication and account lockout
- Monitor for potential denial of service attacks
- Verify affected Payload versions and exposure
- Prioritize upgrades and patches for affected deployments
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and source item provide details on the vulnerability, including the impact, patches, and affected versions. The vulnerability was publicly disclosed on 2026-10-07T20:29:04.000Z. Defenders should verify affected Payload versions and upgrade to >= 3.90.0 or >= 4.0.0-canary.34. The source item and CVE record do not provide additional information on exploitability or affected deployments.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-105866 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-105866
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-105866 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105866
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Payload: Unauthenticated account-lockout denial of service
Unverified legacy reference
URL: https://storage.googleapis.com/osv-vulnerabilities/npm/GHSA-v5gf-vpjc-pc7w.json
osv_dev
-
Source reference
Unverified legacy reference
URL: https://github.com/payloadcms/payload/security/advisories/GHSA-v5gf-vpjc-pc7w
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/payloadcms/payload/commit/1c46204a73a0a9f988a80c52690eee5a4ada3cf1
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/payloadcms/payload
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/payloadcms/payload/releases/tag/v3.90.0
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.