Sceawere

Vulnerability Detail

CVE-2026-105857UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Payload Form Builder RCE

Vulnerability Metadata

Severity
Critical
Score / CVSS
10
Creation Date
8h ago
Vendor
payloadcms
Product
payload
Attack Type
CWE-94: Improper Control of Generation of Code ('Code Injection')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Payload is a free and open source headless content management system. In @payloadcms/plugin-form-builder versions before 3.90.0 and canary versions before 4.0.0-canary.34, an attacker can craft a form submission that executes code remotely on the server. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "10.0",
  "pubDate": "2026-10-06T17:17:21.710Z",
  "pubdate": "2026-10-06T17:17:21.710Z",
  "executiveSummary": "The @payloadcms/plugin-form-builder package is susceptible to a Remote Code Execution (RCE) vulnerability. This security flaw allows a remote, unauthenticated attacker to execute arbitrary system commands on the hosting server by submitting a specifically crafted form payload.\nThe vulnerability originates from improper handling of form submission data, which enables the injection of malicious code into the server environment. Successful exploitation results in complete system compromise, potentially allowing an attacker to access sensitive data, modify application files, or establish persistence within the infrastructure.\nThis vulnerability affects versions of @payloadcms/plugin-form-builder prior to 3.90.0 and versions prior to 4.0.0-canary.34. Due to the high severity of Remote Code Execution vulnerabilities, immediate patching is required to mitigate the risk of unauthorized server-side command execution.",
  "technicalDetails": "The vulnerability resides within the @payloadcms/plugin-form-builder component, specifically in how the plugin processes and handles form submission input. The root cause of this RCE vulnerability is the insecure deserialization or improper sanitization of input data provided through form fields during the submission process.\nWhen a user submits a form, the plugin processes the provided fields to store or handle the data. In the vulnerable versions, the input data is not sufficiently validated or neutralized before being passed to an execution sink. By crafting a malicious form submission payload, an attacker can bypass existing validation layers to inject arbitrary code or commands that the server-side environment subsequently interprets and executes.\nThe attack flow begins with the discovery of the form endpoint, which is exposed to the network to allow user submissions. An attacker does not require prior authentication to interact with these forms. The attacker constructs a payload containing malicious system commands or code instructions embedded within a legitimate form field structure. Upon submission, the plugin fails to properly isolate this input, allowing the underlying Node.js runtime or system shell to evaluate the injected commands.\nBecause the payload is processed at the application layer, the executed commands inherit the privileges of the system process running the Payload CMS instance. This facilitates full Remote Code Execution (RCE), enabling the attacker to perform post-exploitation activities such as exfiltrating database contents, accessing environment variables containing credentials, or pivoting to other segments of the internal network.\nThe flaw affects @payloadcms/plugin-form-builder versions before 3.90.0 and canary versions before 4.0.0-canary.34. The lack of strict input typing and the existence of dangerous sink functions during the submission handling pipeline constitute the primary vectors for this exploit. Systems exposed to the public internet are at significant risk, as the exploitation requirement is limited to the ability to submit form data to the application's API endpoints."
}
CVE-2026-105857: Payload Form Builder RCE (CRITICAL Severity, CVSS: 10.0) | Sceawere