{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/payload/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:payload:payloadcms_storage_s3:*:*:*:*:*:*:*:*"],"_cs_cves":[{"id":"CVE-2026-105867"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["@payloadcms/storage-s3 (\u003c 3.90.0)","@payloadcms/storage-s3 (\u003e= 4.0.0-canary.0, \u003c 4.0.0-canary.34)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","web-application","cloud"],"_cs_type":"advisory","_cs_vendors":["Payload"],"content_html":"\u003cp\u003eThe @payloadcms/storage-s3 package, used for managing file uploads in Payload CMS applications, contains a critical vulnerability (CVE-2026-105867) that allows authenticated users to perform unauthorized file operations. The issue exists when multiple upload collections share the same S3 bucket and the 'useCompositePrefixes' configuration setting is either disabled or missing. In this configuration, the storage driver fails to enforce isolation between different collections, permitting an attacker to craft upload requests that overwrite files belonging to other collections. This bypasses access controls and validation logic intended for the target collections. Organizations using Payload versions prior to 3.90.0 or the affected 4.0.0-canary range are exposed. Impact is restricted to environments where multiple collections share an S3 bucket with 'useCompositePrefixes' set to false.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in the unauthorized modification or destruction of data within an S3 bucket. An attacker can overwrite existing files across different collections, effectively bypassing the security boundaries and validation checks defined for those specific collections. This can be used to replace legitimate application assets or configuration files with malicious content, leading to further compromise depending on how the application processes these files.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately upgrade the @payloadcms/storage-s3 package to version 3.90.0 or later, or 4.0.0-canary.34 or later, to address CVE-2026-105867.\u003c/li\u003e\n\u003cli\u003eIf upgrading is not immediately possible, disable client-side file uploads as a temporary workaround.\u003c/li\u003e\n\u003cli\u003eAudit S3 bucket configurations to verify if multiple collections share a single bucket and ensure 'useCompositePrefixes' is explicitly enabled in the Payload CMS storage configuration.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-07T22:50:06Z","date_published":"2026-10-07T22:50:06Z","id":"https://feed.craftedsignal.io/briefs/2026-10-payload-s3-overwrite/","summary":"An authenticated user can exploit a path configuration weakness in @payloadcms/storage-s3 to overwrite arbitrary S3 objects across collections, bypassing security controls.","title":"Payload Storage-S3 Object Overwrite Vulnerability","url":"https://feed.craftedsignal.io/briefs/2026-10-payload-s3-overwrite/"},{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:payload:payloadcms_plugin_multi_tenant:*:*:*:*:*:*:*:*"],"_cs_cves":[{"id":"CVE-2026-105860"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["@payloadcms/plugin-multi-tenant (\u003c 3.90.0, \u003e= 4.0.0-canary.0 \u003c 4.0.0-canary.34)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","privilege-escalation","cms"],"_cs_type":"advisory","_cs_vendors":["Payload"],"content_html":"\u003cp\u003eThe Payload Multi-Tenant plugin contains an authorization bypass vulnerability (CVE-2026-105860) that permits authenticated users to manipulate tenant assignments. The vulnerability exists within the default tenant array field access configuration. By default, the plugin lacks sufficient restrictions on the 'create' and 'update' functions for the tenants array field, allowing a standard user to modify their own tenant membership. An attacker could exploit this to gain unauthorized access to other tenants, leading to horizontal or vertical privilege escalation. The issue is resolved in version 3.90.0 and version 4.0.0-canary.34. Organizations using the plugin must ensure they implement custom \u003ccode\u003earrayFieldAccess\u003c/code\u003e configurations if they cannot upgrade immediately to enforce proper membership validation.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an authenticated user to gain access to tenants they are not authorized to manage or view. This results in unauthorized data access and potential privilege escalation within the multi-tenant application environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade \u003ccode\u003e@payloadcms/plugin-multi-tenant\u003c/code\u003e to version 3.90.0 or later, or 4.0.0-canary.34 or later to address CVE-2026-105860.\u003c/li\u003e\n\u003cli\u003eIf upgrading is not immediately feasible, configure custom \u003ccode\u003etenants arrayFieldAccess.create\u003c/code\u003e and \u003ccode\u003etenants arrayFieldAccess.update\u003c/code\u003e functions to restrict modifications to users explicitly authorized for all relevant tenants.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-07T22:49:32Z","date_published":"2026-10-07T22:49:32Z","id":"https://feed.craftedsignal.io/briefs/2026-10-payload-auth-bypass/","summary":"An authorization vulnerability in @payloadcms/plugin-multi-tenant allows authenticated users to assign themselves to unauthorized tenants by leveraging default field access configurations.","title":"Authorization Bypass in @payloadcms/plugin-multi-tenant","url":"https://feed.craftedsignal.io/briefs/2026-10-payload-auth-bypass/"},{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"id":"CVE-2026-105856"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["@payloadcms/db-sqlite (\u003c 3.90.0, \u003e= 4.0.0-canary.0 \u003c 4.0.0-canary.34)","@payloadcms/db-d1-sqlite (\u003c 3.90.0, \u003e= 4.0.0-canary.0 \u003c 4.0.0-canary.34)","@payloadcms/db-postgres (\u003c 3.73.0)","@payloadcms/db-vercel-postgres (\u003c 3.73.0)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Payload"],"content_html":"\u003cp\u003ePayload CMS database adapters for SQLite and Postgres contain a SQL injection vulnerability identified as CVE-2026-105856. The flaw exists in the query processing logic when interacting with collections containing 'json' fields or 'blocks' fields configured with 'blocksAsJSON: true'. An attacker who possesses read, create, or update access to such a collection can submit specially crafted requests containing malicious operators or path shapes. By exploiting this insufficient sanitization of query inputs within the database adapter layers, an attacker may be able to manipulate database queries to bypass filters or extract unauthorized data. The vulnerability impacts users of @payloadcms/db-sqlite, @payloadcms/db-d1-sqlite, @payloadcms/db-postgres, and @payloadcms/db-vercel-postgres. Defenders should prioritize upgrading to version 3.90.0 or 4.0.0-canary.34 to remediate this vulnerability.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an authenticated attacker to inject arbitrary SQL commands into the backend database. This could lead to unauthorized data exfiltration, modification of collection contents, or potential service disruption. The risk is constrained to environments where attackers have at least read access to collections configured with JSON-based fields.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade affected Payload CMS database adapter packages immediately to version 3.90.0 or 4.0.0-canary.34.\u003c/li\u003e\n\u003cli\u003eAudit logs for unexpected database query patterns, specifically focusing on POST requests to API endpoints that handle collection creation or updates containing nested JSON payloads.\u003c/li\u003e\n\u003cli\u003eReview collection schemas to identify usage of 'json' fields or 'blocks' fields with 'blocksAsJSON: true' and apply least-privilege access controls to collections utilizing these field types until patches are applied.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-07T22:49:08Z","date_published":"2026-10-07T22:49:08Z","id":"https://feed.craftedsignal.io/briefs/2026-10-payload-sql-injection/","summary":"An improper input sanitization vulnerability in Payload CMS database adapters allows attackers with collection access to execute SQL injection attacks via JSON and block fields.","title":"SQL Injection in Payload CMS SQLite and Postgres Adapters","url":"https://feed.craftedsignal.io/briefs/2026-10-payload-sql-injection/"},{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:payload:payloadcms_plugin_form_builder:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":10,"id":"CVE-2026-105857"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["@payloadcms/plugin-form-builder (\u003c 3.90.0, \u003e= 4.0.0-canary.0 \u003c 4.0.0-canary.34)"],"_cs_severities":["critical"],"_cs_tags":["remote-code-execution","web-application-vulnerability","payloadcms"],"_cs_type":"advisory","_cs_vendors":["Payload"],"content_html":"\u003cp\u003eThe @payloadcms/plugin-form-builder package, used within the Payload CMS ecosystem, contains a critical vulnerability (CVE-2026-105857) that permits remote code execution. The issue stems from insecure handling of user-supplied data during form submissions. Attackers can craft malicious input within a form field that, when processed by the application, is evaluated or executed by the underlying server-side environment. This flaw affects versions of the plugin prior to 3.90.0 and specific versions in the 4.0.0-canary release cycle. Because the vulnerability is triggered via form submission endpoints, it is a high-value target for threat actors looking to gain initial access to servers hosting Payload CMS instances. Immediate patching is required to prevent compromise of the host infrastructure.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability leads to full remote code execution on the application server. This can result in unauthorized data access, lateral movement within the network, and complete system compromise. Organizations running Payload CMS installations using the affected plugin versions are at risk of server takeover.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the @payloadcms/plugin-form-builder package to version 3.90.0 or higher immediately.\u003c/li\u003e\n\u003cli\u003eFor those on the canary track, upgrade to version 4.0.0-canary.34 or higher.\u003c/li\u003e\n\u003cli\u003eMonitor web server access logs for anomalous POST requests directed at form submission endpoints that include unexpected payloads or shell-like characters.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-07T22:46:53Z","date_published":"2026-10-07T22:46:53Z","id":"https://feed.craftedsignal.io/briefs/2026-10-payload-rce/","summary":"A critical remote code execution vulnerability (CVE-2026-105857) in @payloadcms/plugin-form-builder allows unauthenticated attackers to execute arbitrary code via crafted form submissions.","title":"Remote Code Execution in @payloadcms/plugin-form-builder","url":"https://feed.craftedsignal.io/briefs/2026-10-payload-rce/"},{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:payload:plugin_mcp:*:*:*:*:*:*:*:*"],"_cs_cves":[{"id":"CVE-2026-105806"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["plugin-mcp (\u003e= 3.61.0, \u003c 3.88.0)"],"_cs_severities":["high"],"_cs_tags":["privilege-escalation","cms","web-application"],"_cs_type":"advisory","_cs_vendors":["Payload"],"content_html":"\u003cp\u003eThe @payloadcms/plugin-mcp package for Payload CMS is affected by an improper access control vulnerability, tracked as CVE-2026-105806, impacting versions 3.61.0 through 3.87.9. This vulnerability allows an already authenticated user to interact with and manage Model Context Protocol (MCP) API keys belonging to accounts other than their own. By manipulating requests to the API key management endpoints, an attacker can hijack these keys, potentially leading to unauthorized access, further privilege escalation, and full account takeover within the Payload CMS environment. The issue stems from insufficient validation of ownership or permission boundaries during API key management operations. Defenders should prioritize patching, as this flaw directly undermines the security boundaries between users in a multi-tenant or collaborative CMS deployment.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows unauthorized management of security credentials (API keys) across different user accounts within the same Payload CMS instance. If exploited, an attacker can gain control over administrative or higher-privileged API keys, leading to complete account takeover, exfiltration of sensitive CMS data, or unauthorized configuration changes. The impact is significant for organizations relying on the MCP plugin for automated workflows and integrations.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the @payloadcms/plugin-mcp package to version 3.88.0 or later immediately to patch CVE-2026-105806.\u003c/li\u003e\n\u003cli\u003eIf immediate patching is not feasible, disable the MCP plugin functionality until the upgrade is performed.\u003c/li\u003e\n\u003cli\u003eAudit logs for the API key management endpoints in Payload CMS to identify unauthorized access attempts or unusual patterns involving key manipulation from non-administrative users.\u003c/li\u003e\n\u003cli\u003eRestrict access to MCP API-key management interfaces to a highly limited set of trusted users until the software is updated.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-06T18:48:00Z","date_published":"2026-10-06T18:48:00Z","id":"https://feed.craftedsignal.io/briefs/2026-10-payload-mcp-access-control/","summary":"An improper access control vulnerability (CVE-2026-105806) in the @payloadcms/plugin-mcp package allows authenticated users to manage API keys across accounts, facilitating privilege escalation and account takeover.","title":"Improper Access Control in Payload CMS MCP Plugin","url":"https://feed.craftedsignal.io/briefs/2026-10-payload-mcp-access-control/"},{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:payloadcms:payload:*:*:*:*:*:node.js:*:*"],"_cs_cves":[{"id":"CVE-2026-105849"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["payload (\u003e= 3.0.0 \u003c 3.90.0, \u003e= 4.0.0-canary.0 \u003c 4.0.0-canary.34)","Payload (\u003e= 3.0.0, \u003c 3.90.0)","Payload (\u003e= 4.0.0-canary.0, \u003c 4.0.0-canary.34)","Payload (3.0.0 - 3.89.9)","Payload (4.0.0-canary.0 - 4.0.0-canary.33)","Payload (3.0.0 \u003c= version \u003c 3.88.0, 4.0.0-canary.0 \u003c= version \u003c 4.0.0-canary.27)","Payload (v3.x \u003c 3.87.0)","Payload (v4.0.0-canary \u003c 4.0.0-canary.20)","Payload (\u003c 3.90.0, \u003e= 4.0.0-canary.0 \u003c 4.0.0-canary.34)","Payload (v3.0.0 to \u003c3.90.0)","Payload (v4.0.0-canary.0 to \u003c4.0.0-canary.34)","Payload (\u003c 3.90.0)","Payload (\u003c 3.90.0, \u003e= 4.0.0-canary.0, \u003c 4.0.0-canary.34)"],"_cs_severities":["critical"],"_cs_tags":["information-disclosure","cms","authentication","web-application","cve-2026-105847","web-vulnerability","access-control","sqli","vulnerability","high-confidence-source","remote-code-execution","web-application-vulnerability","session-hijacking","credential-theft","cve-2026-105861","xss","web-security","file-deletion","path-traversal","content-management-system"],"_cs_type":"advisory","_cs_vendors":["Payload"],"content_html":"\u003cp\u003ePayload CMS versions prior to 3.90.0 and 4.0.0-canary.34 are vulnerable to an API key disclosure flaw, tracked as CVE-2026-105849. This vulnerability manifests in deployments where the \u003ccode\u003euseAPIKey\u003c/code\u003e authentication feature is enabled. Due to insecure access control logic, users who possess read access to documents within an authentication collection can view sensitive API keys belonging to other users. Because these keys hold the permissions of the target account, successful exploitation allows an attacker to masquerade as the compromised user until the key is rotated or disabled. This impacts organizations relying on Payload for authentication and document management, particularly those with permissive document access policies.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthorized users to retrieve valid API keys of other users, leading to account takeover. The impact is significant for applications where API keys manage sensitive operations or provide access to protected administrative functions. Users must immediately verify document read permissions and rotate any keys potentially exposed during the window of vulnerability.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Payload CMS to version 3.90.0 or 4.0.0-canary.34 to patch CVE-2026-105849.\u003c/li\u003e\n\u003cli\u003eAudit document read permissions in the CMS and restrict access to authentication collections to authorized users only.\u003c/li\u003e\n\u003cli\u003eDisable the \u003ccode\u003euseAPIKey\u003c/code\u003e feature if not strictly required for application functionality.\u003c/li\u003e\n\u003cli\u003ePerform a mandatory rotation of all active API keys generated while the affected versions were in use to mitigate potential unauthorized access.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-07T22:50:22Z","date_published":"2026-10-06T18:47:38Z","id":"https://feed.craftedsignal.io/briefs/2026-10-payload-api-key-disclosure/","summary":"A vulnerability in Payload CMS versions 3.x and 4.x-canary allows unauthorized users with document read permissions to access active API keys stored within authentication collections.","title":"Payload API Key Disclosure via Document Read Access","url":"https://feed.craftedsignal.io/briefs/2026-10-payload-api-key-disclosure/"},{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:payload:plugin_import_export:*:*:*:*:*:*:*:*"],"_cs_cves":[{"id":"CVE-2026-105844"}],"_cs_exploited":false,"_cs_has_poc":true,"_cs_poc_references":["https://sploitus.com/exploit?id=73BE1B4F-C08C-5F0A-9943-93A0A290FB8E\u0026utm_source=rss\u0026utm_medium=rss"],"_cs_products":["plugin-import-export (3.0.0 - 3.87.9)","plugin-import-export (4.0.0-canary.0 - 4.0.0-canary.26)"],"_cs_severities":["critical"],"_cs_tags":["web-application","prototype-pollution","rce","supply-chain"],"_cs_type":"advisory","_cs_vendors":["Payload"],"content_html":"\u003cp\u003eA prototype pollution vulnerability has been identified in the @payloadcms/plugin-import-export package, tracked as CVE-2026-105844. This vulnerability affects versions 3.0.0 through 3.87.9 and canary versions between 4.0.0-canary.0 and 4.0.0-canary.26. The flaw exists within the plugin's data handling logic, which fails to properly sanitize input before processing. An unauthenticated attacker can exploit this weakness by submitting specifically crafted JSON payloads to the plugin's endpoints. By polluting the object prototype, the attacker can influence application-wide behavior, potentially leading to remote code execution (RCE). This issue is limited to environments where the Import Export plugin is explicitly enabled.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an unauthenticated attacker to achieve remote code execution within the context of the Payload CMS application. This could result in full system compromise, data theft, or service disruption. All organizations utilizing the affected plugin version are at risk if the application is internet-facing or accessible to untrusted users.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the @payloadcms/plugin-import-export package to version 3.88.0 or 4.0.0-canary.27 or later.\u003c/li\u003e\n\u003cli\u003eIf an immediate upgrade is not feasible, disable the Import Export plugin entirely or implement strict network-level access controls to restrict access to the plugin's API endpoints.\u003c/li\u003e\n\u003cli\u003eMonitor web application logs for unexpected JSON structures or suspicious requests directed at import or export functional routes.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-07T20:51:04Z","date_published":"2026-10-06T18:45:50Z","id":"https://feed.craftedsignal.io/briefs/2026-10-payload-prototype-pollution/","summary":"An unauthenticated prototype pollution vulnerability in the Payload Import Export plugin allows remote attackers to achieve code execution via malicious input.","title":"Prototype Pollution Vulnerability in Payload Import Export Plugin","url":"https://feed.craftedsignal.io/briefs/2026-10-payload-prototype-pollution/"}],"language":"en","title":"CraftedSignal Threat Feed - Payload","version":"https://jsonfeed.org/version/1.1"}