← Back to CVE List
CVE-2026-105863NVD
Vulnerability Summary
Payload is a free and open source headless content management system. In versions after 3.0.0 and before 3.90.0, a custom field option that maps a field to a reserved authentication claim name can place unintended values in the authentication token issued at login. This issue is fixed in version 3.90.0.
CVSS v4.0 Base Metrics — Score 9.2 (CRITICAL)
Attack VectorNetwork
Attack ComplexityLow
Attack RequirementsPresent
Privileges RequiredNone
User InteractionNone
Confidentiality (Vulnerable System)High
Integrity (Vulnerable System)High
Availability (Vulnerable System)High
Confidentiality (Subsequent System)None
Integrity (Subsequent System)None
Availability (Subsequent System)None
Affected & Patched Versions
- payloadcms payload >= >= 3.0.0, < 3.90.0
- payloadcms payload >= >= 4.0.0-canary.0, < 4.0.0-canary.34
Not provided by cveorg for this CVE.