๐Ÿ” CVE Alert

CVE-2026-105863

UNKNOWN 0.0

Payload authentication token field handling issue

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Payload is a free and open source headless content management system. In versions after 3.0.0 and before 3.90.0, a custom field option that maps a field to a reserved authentication claim name can place unintended values in the authentication token issued at login. This issue is fixed in version 3.90.0.

CWE CWE-290 CWE-915
Vendor payloadcms
Product payload
Published Oct 6, 2026
Stay Ahead of the Next One

Get instant alerts for payloadcms payload

Be the first to know when new unknown vulnerabilities affecting payloadcms payload are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

payloadcms / payload
>= 3.0.0, < 3.90.0 >= 4.0.0-canary.0, < 4.0.0-canary.34

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/payloadcms/payload/security/advisories/GHSA-66wr-7vmr-p5jq github.com: https://github.com/payloadcms/payload/commit/56cd5cd050a57daebf33159e41e5ff9d4a45239c github.com: https://github.com/payloadcms/payload/releases/tag/v3.90.0