{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/@payloadcms/storage-s3--4.0.0-canary.0--4.0.0-canary.34/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:payload:payloadcms_storage_s3:*:*:*:*:*:*:*:*"],"_cs_cves":[{"id":"CVE-2026-105867"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["@payloadcms/storage-s3 (\u003c 3.90.0)","@payloadcms/storage-s3 (\u003e= 4.0.0-canary.0, \u003c 4.0.0-canary.34)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","web-application","cloud"],"_cs_type":"advisory","_cs_vendors":["Payload"],"content_html":"\u003cp\u003eThe @payloadcms/storage-s3 package, used for managing file uploads in Payload CMS applications, contains a critical vulnerability (CVE-2026-105867) that allows authenticated users to perform unauthorized file operations. The issue exists when multiple upload collections share the same S3 bucket and the 'useCompositePrefixes' configuration setting is either disabled or missing. In this configuration, the storage driver fails to enforce isolation between different collections, permitting an attacker to craft upload requests that overwrite files belonging to other collections. This bypasses access controls and validation logic intended for the target collections. Organizations using Payload versions prior to 3.90.0 or the affected 4.0.0-canary range are exposed. Impact is restricted to environments where multiple collections share an S3 bucket with 'useCompositePrefixes' set to false.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in the unauthorized modification or destruction of data within an S3 bucket. An attacker can overwrite existing files across different collections, effectively bypassing the security boundaries and validation checks defined for those specific collections. This can be used to replace legitimate application assets or configuration files with malicious content, leading to further compromise depending on how the application processes these files.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately upgrade the @payloadcms/storage-s3 package to version 3.90.0 or later, or 4.0.0-canary.34 or later, to address CVE-2026-105867.\u003c/li\u003e\n\u003cli\u003eIf upgrading is not immediately possible, disable client-side file uploads as a temporary workaround.\u003c/li\u003e\n\u003cli\u003eAudit S3 bucket configurations to verify if multiple collections share a single bucket and ensure 'useCompositePrefixes' is explicitly enabled in the Payload CMS storage configuration.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-07T22:50:06Z","date_published":"2026-10-07T22:50:06Z","id":"https://feed.craftedsignal.io/briefs/2026-10-payload-s3-overwrite/","summary":"An authenticated user can exploit a path configuration weakness in @payloadcms/storage-s3 to overwrite arbitrary S3 objects across collections, bypassing security controls.","title":"Payload Storage-S3 Object Overwrite Vulnerability","url":"https://feed.craftedsignal.io/briefs/2026-10-payload-s3-overwrite/"}],"language":"en","title":"CraftedSignal Threat Feed - @Payloadcms/Storage-S3 (\u003e= 4.0.0-Canary.0, \u003c 4.0.0-Canary.34)","version":"https://jsonfeed.org/version/1.1"}