<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>@Payloadcms/Storage-S3 (&lt; 3.90.0) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/@payloadcms/storage-s3--3.90.0/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 07 Oct 2026 22:50:06 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/@payloadcms/storage-s3--3.90.0/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Payload Storage-S3 Object Overwrite Vulnerability</title><link>https://feed.craftedsignal.io/briefs/2026-10-payload-s3-overwrite/</link><pubDate>Wed, 07 Oct 2026 22:50:06 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-payload-s3-overwrite/</guid><description>An authenticated user can exploit a path configuration weakness in @payloadcms/storage-s3 to overwrite arbitrary S3 objects across collections, bypassing security controls.</description><content:encoded><![CDATA[<p>The @payloadcms/storage-s3 package, used for managing file uploads in Payload CMS applications, contains a critical vulnerability (CVE-2026-105867) that allows authenticated users to perform unauthorized file operations. The issue exists when multiple upload collections share the same S3 bucket and the 'useCompositePrefixes' configuration setting is either disabled or missing. In this configuration, the storage driver fails to enforce isolation between different collections, permitting an attacker to craft upload requests that overwrite files belonging to other collections. This bypasses access controls and validation logic intended for the target collections. Organizations using Payload versions prior to 3.90.0 or the affected 4.0.0-canary range are exposed. Impact is restricted to environments where multiple collections share an S3 bucket with 'useCompositePrefixes' set to false.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in the unauthorized modification or destruction of data within an S3 bucket. An attacker can overwrite existing files across different collections, effectively bypassing the security boundaries and validation checks defined for those specific collections. This can be used to replace legitimate application assets or configuration files with malicious content, leading to further compromise depending on how the application processes these files.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Immediately upgrade the @payloadcms/storage-s3 package to version 3.90.0 or later, or 4.0.0-canary.34 or later, to address CVE-2026-105867.</li>
<li>If upgrading is not immediately possible, disable client-side file uploads as a temporary workaround.</li>
<li>Audit S3 bucket configurations to verify if multiple collections share a single bucket and ensure 'useCompositePrefixes' is explicitly enabled in the Payload CMS storage configuration.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>web-application</category><category>cloud</category></item></channel></rss>