Skip to content
Threat Feed
high advisory

Payload Storage-S3 Object Overwrite Vulnerability

An authenticated user can exploit a path configuration weakness in @payloadcms/storage-s3 to overwrite arbitrary S3 objects across collections, bypassing security controls.

CVE search metadata

CVE search record: CVE-2026-105867. KEV: no. Product: @payloadcms/storage-s3 (< 3.90.0), @payloadcms/storage-s3 (>= 4.0.0-canary.0, < 4.0.0-canary.34). Brief: Payload Storage-S3 Object Overwrite Vulnerability. Brief link: https://feed.craftedsignal.io/briefs/2026-10-payload-s3-overwrite/

The @payloadcms/storage-s3 package, used for managing file uploads in Payload CMS applications, contains a critical vulnerability (CVE-2026-105867) that allows authenticated users to perform unauthorized file operations. The issue exists when multiple upload collections share the same S3 bucket and the 'useCompositePrefixes' configuration setting is either disabled or missing. In this configuration, the storage driver fails to enforce isolation between different collections, permitting an attacker to craft upload requests that overwrite files belonging to other collections. This bypasses access controls and validation logic intended for the target collections. Organizations using Payload versions prior to 3.90.0 or the affected 4.0.0-canary range are exposed. Impact is restricted to environments where multiple collections share an S3 bucket with 'useCompositePrefixes' set to false.

Impact

Successful exploitation results in the unauthorized modification or destruction of data within an S3 bucket. An attacker can overwrite existing files across different collections, effectively bypassing the security boundaries and validation checks defined for those specific collections. This can be used to replace legitimate application assets or configuration files with malicious content, leading to further compromise depending on how the application processes these files.

Recommendation

  • Immediately upgrade the @payloadcms/storage-s3 package to version 3.90.0 or later, or 4.0.0-canary.34 or later, to address CVE-2026-105867.
  • If upgrading is not immediately possible, disable client-side file uploads as a temporary workaround.
  • Audit S3 bucket configurations to verify if multiple collections share a single bucket and ensure 'useCompositePrefixes' is explicitly enabled in the Payload CMS storage configuration.

Immediate actions

Upgrade @payloadcms/storage-s3 to >= 3.90.0 or >= 4.0.0-canary.34

IT Operations 48h

Mitigations

Disable client uploads until the package is updated

immediate Application Security

CVE-2026-105867