---
id: CVE-2026-105849
title: Payload is a free and open source headless content management system
summary: >-
  Payload is a free and open source headless content management system. In
  versions from 3.0.0 before 3.90.0 and canary versions before 4.0.0-canary.34,
  users with ordinary read access to other authentication documents in a
  collection with…
severity: high
cvss: 7.7
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'
cwe:
  - CWE-201
  - CWE-862
vendor: payloadcms
product: payload
affected:
  - 'payload >= 3.0.0, < 3.90.0'
  - 'payload >= 4.0.0-canary.0, < 4.0.0-canary.34'
patched:
  - payload 3.90.0
  - payload 4.0.0-canary.34
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T18:16:48.367'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-105849'
references:
  - url: >-
      https://github.com/payloadcms/payload/commit/880d2e900be22cd66a9e939f2b3e702fa413180f
    label: security-advisories@github.com
  - url: 'https://github.com/payloadcms/payload/releases/tag/v3.90.0'
    label: security-advisories@github.com
  - url: >-
      https://github.com/payloadcms/payload/security/advisories/GHSA-238x-w2j9-gwwr
    label: security-advisories@github.com
  - url: 'https://github.com/advisories/GHSA-238x-w2j9-gwwr'
tags:
  - nvd
  - cve.org
  - ghsa
  - npm
aliases:
  - GHSA-238x-w2j9-gwwr
ecosystem: npm
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-10-06T17:26:14.965583Z'
cvssSource: cna
ingestedAt: '2026-10-06T17:09:22.182Z'
---

## Overview

Payload is a free and open source headless content management system. In versions from 3.0.0 before 3.90.0 and canary versions before 4.0.0-canary.34, users with ordinary read access to other authentication documents in a collection with useAPIKey enabled can obtain active API keys and exercise the target accounts' permissions until those keys are rotated or disabled. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-105849)

Affected packages:

- `payload >= 3.0.0, < 3.90.0`
- `payload >= 4.0.0-canary.0, < 4.0.0-canary.34`

Patched in:

- `payload 3.90.0`
- `payload 4.0.0-canary.34`

Source: https://github.com/advisories/GHSA-238x-w2j9-gwwr
