---
id: CVE-2026-105865
title: Payload is a free and open source headless content management system
summary: >-
  Payload is a free and open source headless content management system. In
  versions before 3.90.0 and canary versions before 4.0.0-canary.34, an
  authenticated user who can update or delete uploads stored locally can cause
  file cleanup to r…
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'
cwe:
  - CWE-22
  - CWE-73
vendor: payloadcms
product: payload
affected:
  - payload < 3.90.0
  - 'payload >= 4.0.0-canary.0, < 4.0.0-canary.34'
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T18:16:49.947'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-105865'
references:
  - url: >-
      https://github.com/payloadcms/payload/commit/6b74418f628fa633c2f297e5919a9f91b383dc11
    label: security-advisories@github.com
  - url: 'https://github.com/payloadcms/payload/releases/tag/v3.90.0'
    label: security-advisories@github.com
  - url: >-
      https://github.com/payloadcms/payload/security/advisories/GHSA-p223-2wr2-j562
    label: security-advisories@github.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-10-06T17:10:04.066384Z'
ingestedAt: '2026-10-06T17:09:22.190Z'
---

## Overview

Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, an authenticated user who can update or delete uploads stored locally can cause file cleanup to remove unintended files outside the configured upload directory, resulting in data loss or service disruption. Deployments that restrict upload management to trusted users are less exposed. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
