CVE-2026-105866Medium· 6.9▾ SunlitPayload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, an unauthenticated attacker who knows an account email address or username can abuse the account …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 38 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake. The CVSS score shown above comes from the assigning CNA record, not NVD.
Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, an unauthenticated attacker who knows an account email address or username can abuse the account lockout mechanism of a local-authentication collection to prevent that account from signing in. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-105856High· 8.6Payload is a free and open source headless content management system
CVE-2026-105857Critical· 10.0Payload is a free and open source headless content management system
CVE-2026-105858High· 8.1Payload is a free and open source headless content management system
CVE-2026-105859Critical· 9.8Payload is a free and open source headless content management system
CVE-2026-105860High· 7.1Payload is a free and open source headless content management system
CVE-2026-105861High· 7.2Payload is a free and open source headless content management system