CVE-2026-105859Critical· 9.8▾ MidnightPayload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, an attacker can submit a request to a specific update endpoint that modifies collection documents…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 53.9 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, an attacker can submit a request to a specific update endpoint that modifies collection documents without enforcing collection or field-level access control when orderable is enabled on a collection or join field. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
payload < 3.90.0payload >= 4.0.0-canary.0, < 4.0.0-canary.34Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-105860High· 7.1Payload: Tenant authorization bypass in Multi-Tenant Plugin
CVE-2026-105867High· 7.1Payload: Client uploads could overwrite S3 objects
CVE-2026-105847High· 7.1Payload: Polymorphic join queries could disclose hidden fields
CVE-2026-105852Medium· 6.9Payload relationship-query authorization bypass
CVE-2026-105849High· 7.7Payload vulnerable to API key disclosure through ordinary document reads
CVE-2026-105857Critical· 10.0Payload: RCE in Payload Form Builder