CRITICAL 9.2 NVD
CVE-2026-105863
Payload is a free and open source headless content management system. In versions after 3.0.0 and before 3.90.0, a custom field option that maps a field to a re
Payload is a free and open source headless content management system. In versions after 3.0.0 and before 3.90.0, a custom field option that maps a field to a reserved authentication claim name can place unintended values in the authentication token issued at login. This issue is fixed in version 3.90.0.
References
- https://github.com/payloadcms/payload/commit/56cd5cd050a57daebf33159e41e5ff9d4a45239c
- https://github.com/payloadcms/payload/releases/tag/v3.90.0
- https://github.com/payloadcms/payload/security/advisories/GHSA-66wr-7vmr-p5jq
This critical severity vulnerability with a CVSS score of 9.2 was published on 2026-10-06 via NVD.
Risk Timeline
CVE Disclosed2026-10-06 · -1 days ago
Remediation Resources
vulnfeed aggregates 9311 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.