CYBER CODE RED

Get real-time updates on Telegram

Verified

CVE-2026-105867: payload < 3.90.0, >= 4.0.0-canary.0, < 4.0.0-canary.34; +1 more affected products

Affected technology

payload · < 3.90.0, >= 4.0.0-canary.0, < 4.0.0-canary.34
payloadcms

storage-s3 · < 3.90.0, >= 4.0.0-canary.0, < 4.0.0-canary.34
@payloadcms

Component: Not specified by the source

Attack conditions (Vendor/CNA, CVSS 4.0): Network (remote) · Low privileges required · No user interaction required

What an attacker can do

An authenticated user can overwrite an existing S3 object belonging to another upload collection when client uploads are enabled for multiple collections sharing a bucket and useCompositePrefixes is false or unset. Vendor/CNA’s CVSS 4.0 assessment (base score 7.1/10) rates confidentiality impact as none; integrity impact as high; availability impact as low.

Published

CWE
CWE-639
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-105867.html