← Back to CVE List
CVE-2026-105867NVD
Vulnerability Summary
Payload is a free and open source headless content management system. In @payloadcms/storage-s3 versions before 3.90.0 and canary versions before 4.0.0-canary.34, an authenticated user can overwrite an existing S3 object belonging to another upload collection when client uploads are enabled for multiple collections sharing a bucket and useCompositePrefixes is false or unset. This bypasses the target collection's access controls and prior file validation. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
CVSS v4.0 Base Metrics — Score 7.1 (HIGH)
Attack VectorNetwork
Attack ComplexityLow
Attack RequirementsNone
Privileges RequiredLow
User InteractionNone
Confidentiality (Vulnerable System)None
Integrity (Vulnerable System)High
Availability (Vulnerable System)Low
Confidentiality (Subsequent System)None
Integrity (Subsequent System)None
Availability (Subsequent System)None
Affected & Patched Versions
- payloadcms payload >= < 3.90.0
- payloadcms payload >= >= 4.0.0-canary.0, < 4.0.0-canary.34
- @payloadcms storage-s3 >= < 3.90.0
- @payloadcms storage-s3 >= >= 4.0.0-canary.0, < 4.0.0-canary.34
Not provided by cveorg for this CVE.