Description
Payload is a free and open source headless content management system. In versions after 3.0.0 and before 3.90.0, authenticated external URL-based upload retrieval can forward authentication data to a redirected destination that was not verified as trusted, potentially exposing a valid session to an unintended recipient. This issue is fixed in version 3.90.0.
Published: 2026-10-06
Score: 7.2 High
EPSS: n/a
KEV: No
Impact: Session Exposure (Authenticated Redirect to Untrusted Resource)
Action: Immediate Patch
AI Analysis

Impact

The flaw allows an authenticated user to trigger an external URL-based file upload that follows a redirect to a destination not verified as trusted. During the redirect, the original authentication data can be forwarded to the new host, potentially leaking a valid session to an unintended recipient. This exposes the attacker to the authenticated user's session and any privileges associated with it. The weakness is reflected in CWE-200 (Information Exposure) and CWE-346 (Untrusted Resource Redirect).

Affected Systems

Payload CMS by PayloadCMS, specifically the product named "payload". All releases greater than version 3.0.0 and up to, but not including, version 3.90.0 are affected.

Risk and Exploitability

With a CVSS score of 7.2, this vulnerability carries a moderate to high severity. The EPSS score is not available, and the issue is not listed in CISA’s KEV catalog, indicating that it has not yet been widely exploited. The likely attack path requires a legitimate authenticated session to initiate an upload of a file from an external URL that redirects to a hostile server. Attackers would need to control or know the redirect target to capture the authentication data; the exploitation does not require local privileges or code execution. Because the vulnerability hinges on redirect handling, it is harder to exploit than a simple injection flaw, but it can still provide an attacker with a legitimate session token if execution conditions are met.

Generated by OpenCVE AI on October 6, 2026 at 17:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Payload CMS to version 3.90.0 or later, which contains the fix for the redirect trust validation issue.
  • If an upgrade cannot be performed immediately, disable external URL-based uploads or enforce strict validation of redirect targets in your deployment configuration.
  • Avoid uploading files from untrusted external URLs until the patched version is installed; monitor for any suspicious redirects that may carry authentication tokens.

Generated by OpenCVE AI on October 6, 2026 at 17:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 16:45:00 +0000

Type Values Removed Values Added
Description Payload is a free and open source headless content management system. In versions after 3.0.0 and before 3.90.0, authenticated external URL-based upload retrieval can forward authentication data to a redirected destination that was not verified as trusted, potentially exposing a valid session to an unintended recipient. This issue is fixed in version 3.90.0.
Title Payload external upload trust validation issue
Weaknesses CWE-200
CWE-346
References
Metrics cvssV4_0

{'score': 7.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-06T17:39:16.866Z

Reserved: 2026-10-05T23:06:29.748Z

Link: CVE-2026-105861

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-06T17:17:22.277

Modified: 2026-10-06T18:16:49.577

Link: CVE-2026-105861

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T18:00:05Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-346

    Origin Validation Error