Description
Payload is a free and open source headless content management system. Prior to 3.90.0 and 4.0.0-canary.34, an attacker with read and create or update access to a collection containing a json field or a blocks field with blocksAsJSON enabled can inject SQL through a crafted field path and operators. Collections without those fields are not affected, and richText fields are not affected. The SQLite packages are fixed in versions 3.90.0 and 4.0.0-canary.34, and the Postgres packages are fixed in version 3.73.0.
Published: 2026-10-06
Score: 8.6 High
EPSS: n/a
KEV: No
Impact: SQL injection
Action: Patch
AI Analysis

Impact

Payload, a free open‑source headless CMS, contains a vulnerability that allows an attacker with read or create/update rights on a collection that includes a JSON field or a blocks field with blocksAsJSON enabled to inject SQL via a crafted field path and operators. This weakness can result in arbitrary SQL execution against the underlying SQLite or Postgres database, exposing all data stored in that database and potentially allowing further exploitation such as privilege escalation or data exfiltration.

Affected Systems

The vulnerability affects Payload CMS installations using the SQLite and Postgres database adapters supplied by @payloadcms. Specifically, any collection containing a JSON field or a blocks field with blocksAsJSON enabled is vulnerable if the user has read or create/update access. Collections lacking these fields or richText fields are not affected. The SQLite adapters shipped in versions prior to 3.90.0 and 4.0.0‑canary.34 are impacted, while the Postgres adapters prior to version 3.73.0 are affected.

Risk and Exploitability

The CVSS score of 8.6 indicates high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Attack requires attacker access to the CMS with at least read rights, and the attacker must be able to supply a crafted field path and operators in a collection that contains the vulnerable field types. With these conditions met, the attacker can execute arbitrary SQL commands against the database. No public exploits are known, but the high score and the exposure of all database data make it a priority target for attackers.

Generated by OpenCVE AI on October 6, 2026 at 17:58 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the SQLite adapter to version 3.90.0 or later, or to 4.0.0‑canary.34 or later, which contain the SQL injection fix.
  • Upgrade the Postgres adapter to version 3.73.0 or later, which also removes the vulnerability.
  • If an upgrade cannot be performed immediately, restrict users who have create or update rights to collections that contain JSON or blocks fields, or re‑architect those fields to remove blocksAsJSON and apply strict input validation to prevent injection of arbitrary SQL.

Generated by OpenCVE AI on October 6, 2026 at 17:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 16:45:00 +0000

Type Values Removed Values Added
Description Payload is a free and open source headless content management system. Prior to 3.90.0 and 4.0.0-canary.34, an attacker with read and create or update access to a collection containing a json field or a blocks field with blocksAsJSON enabled can inject SQL through a crafted field path and operators. Collections without those fields are not affected, and richText fields are not affected. The SQLite packages are fixed in versions 3.90.0 and 4.0.0-canary.34, and the Postgres packages are fixed in version 3.73.0.
Title Payload: SQL injection in SQLite/Postgres
Weaknesses CWE-89
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-06T17:39:22.911Z

Reserved: 2026-10-05T23:06:29.748Z

Link: CVE-2026-105856

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-06T17:17:21.570

Modified: 2026-10-06T18:16:48.967

Link: CVE-2026-105856

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T18:00:05Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')