Description
Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, an attacker can submit a request to a specific update endpoint that modifies collection documents without enforcing collection or field-level access control when orderable is enabled on a collection or join field. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
Published: 2026-10-06
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: Unauthorized Data Modification
Action: Immediate Patch
AI Analysis

Impact

The flaw allows an attacker to send a request to a specific update endpoint that modifies collection documents without enforcing collection or field‑level authorization checks when the 'orderable' setting is enabled. This bypass reflects missing authorization controls (CWE‑639, CWE‑862) and lets an attacker arbitrarily change any data stored in those collections, potentially inserting malicious content or performing mass updates. No arbitrary code execution is required; the flaw is purely a data integrity issue.

Affected Systems

PayloadCMS installations running any public release older than 3.90.0, or any canary build older than 4.0.0‑canary.34, are affected. Those instances in which the 'orderable' feature is enabled on a collection or join field are vulnerable.

Risk and Exploitability

The CVSS score of 9.8 indicates a high severity. Because the exploit is remote and relies only on sending an HTTP request to the vulnerable update endpoint, it is practically exploitable for any installation where the ‘orderable’ option is enabled. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, but the lack of proper authorization controls (CWE‑639, CWE‑862) creates a significant risk of data integrity compromise.

Generated by OpenCVE AI on October 6, 2026 at 18:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to PayloadCMS 3.90.0 or later, or to canary release 4.0.0‑canary.34, which restores enforced collection and field‑level access checks.
  • If an immediate upgrade is not possible, disable the 'orderable' setting on all vulnerable collections or join fields to block unauthorized updates through the endpoint.
  • Add explicit authorization verification to the update endpoint, ensuring that the request context satisfies role‑based permissions and addressing the CWE‑639 and CWE‑862 weaknesses before applying any modifications.
  • Continue to monitor PayloadCMS security advisories and apply future patches without delay.

Generated by OpenCVE AI on October 6, 2026 at 18:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 16:45:00 +0000

Type Values Removed Values Added
Description Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, an attacker can submit a request to a specific update endpoint that modifies collection documents without enforcing collection or field-level access control when orderable is enabled on a collection or join field. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
Title Payload: Unauthorized update to collection documents
Weaknesses CWE-639
CWE-862
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-06T17:37:22.423Z

Reserved: 2026-10-05T23:06:29.748Z

Link: CVE-2026-105859

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-06T17:17:21.987

Modified: 2026-10-06T18:16:49.300

Link: CVE-2026-105859

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T18:30:05Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key

  • CWE-862

    Missing Authorization