Description
Payload is a free and open source headless content management system. In @payloadcms/plugin-form-builder versions before 3.90.0 and canary versions before 4.0.0-canary.34, an attacker can craft a form submission that executes code remotely on the server. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
Published: 2026-10-06
Score: 10 Critical
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

An attacker can submit a specially crafted form via the Payload CMS form builder plugin, allowing remote execution of arbitrary code on the hosting server. The vulnerability stems from improper validation of form payloads and the use of unsafe evaluation functions (CWE‑1321 and CWE‑94). Successful exploitation compromises server confidentiality, integrity, and availability by enabling attacker‑controlled commands.

Affected Systems

Payload CMS, specifically the form builder plugin in versions earlier than 3.90.0 and canary releases before 4.0.0‑canary.34, is susceptible. Updating to v3.90.0 or v4.0.0‑canary.34 removes the flaw.

Risk and Exploitability

The CVSS score of 10 indicates critical severity, and the lack of an EPSS score shows current exploit data is unavailable; however, the vulnerability is listed in the official advisories and has a direct web‑based attack path via form submissions. An attacker who can reach the form endpoint can trigger code execution, implying high risk for exposed installations. The risk warrants urgent remediation.

Generated by OpenCVE AI on October 6, 2026 at 17:57 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Payload CMS form builder plugin to version 3.90.0 or later, and apply any host system patches.
  • If the plugin cannot be upgraded immediately, disable or remove the form builder to eliminate the attack surface.
  • Validate and sanitize all incoming form data on the server side to prevent execution of arbitrary code.
  • Restrict access to the form endpoint to trusted IP ranges or authenticated users to reduce exposure.

Generated by OpenCVE AI on October 6, 2026 at 17:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 16:45:00 +0000

Type Values Removed Values Added
Description Payload is a free and open source headless content management system. In @payloadcms/plugin-form-builder versions before 3.90.0 and canary versions before 4.0.0-canary.34, an attacker can craft a form submission that executes code remotely on the server. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
Title Payload: RCE in Payload Form Builder
Weaknesses CWE-1321
CWE-94
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-06T17:23:32.964Z

Reserved: 2026-10-05T23:06:29.748Z

Link: CVE-2026-105857

cve-icon Vulnrichment

Updated: 2026-10-06T17:23:28.261Z

cve-icon NVD

Status : Received

Published: 2026-10-06T17:17:21.710

Modified: 2026-10-06T18:16:49.103

Link: CVE-2026-105857

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T18:00:05Z

Weaknesses
  • CWE-1321

    Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

  • CWE-94

    Improper Control of Generation of Code ('Code Injection')