Sceawere
Vulnerability Detail
CVE-2026-105858UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Payload CMS Remote Code Execution
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.1
- Creation Date
- 8h ago
- Vendor
- payloadcms
- Product
- payload
- Attack Type
- CWE-94: Improper Control of Generation of Code ('Code Injection')
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, a crafted request to the public first-register operation can execute code remotely when local authentication is enabled and no initial user has been created. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.1",
"pubDate": "2026-10-06T17:17:21.847Z",
"pubdate": "2026-10-06T17:17:21.847Z",
"executiveSummary": "Payload, a headless content management system, is susceptible to a critical Remote Code Execution (RCE) vulnerability stemming from improper input handling within the public first-register operation.\nThe vulnerability allows an unauthenticated, remote attacker to execute arbitrary code on the underlying server. This flaw exists when local authentication is enabled but the application has not yet been initialized with an initial administrative user.\nGiven the severity of RCE, the impact includes full system compromise, data exfiltration, unauthorized access to internal resources, and potential lateral movement within the network.\nThe risk is categorized as critical, as it bypasses standard security controls during the initial setup phase. Successful exploitation requires no prior authentication, targeting the window of opportunity before the CMS is hardened through user creation.\nOrganizations using Payload should prioritize upgrading to the patched versions immediately to remediate the vulnerability and mitigate the risk of unauthorized system-level command execution.",
"technicalDetails": "The vulnerability resides in the initialization process of Payload CMS, specifically within the public first-register operation intended to facilitate the creation of the initial system administrator. The flaw occurs due to insufficient input validation and insecure deserialization or unsafe processing of data provided during this initial registration request.\nWhen Payload is deployed with local authentication enabled and the system detects that no administrator account exists, it exposes an endpoint to register the first user. Attackers can leverage this uninitialized state by sending a specially crafted HTTP request to this endpoint.\nThe exploitation flow initiates by interacting with the public first-register operation before any administrative account is established. By injecting malicious payloads into parameters expected by the registration function, an attacker can manipulate the application's runtime environment.\nBecause the registration process lacks adequate sanitization or boundary checks during this boot-strapping phase, the crafted request allows for the injection of arbitrary code that is subsequently interpreted and executed by the server-side runtime.\nAffected versions include Payload versions prior to 3.90.0 and canary versions prior to 4.0.0-canary.34. The vulnerability is restricted to the specific condition where the CMS is in an 'uninitialized' state, making newly deployed instances the primary targets for exploitation.\nPost-exploitation, the attacker gains the ability to execute system commands with the privileges of the Node.js process running the Payload CMS instance. This typically results in a full compromise of the host machine, potentially allowing the attacker to persist, install backdoors, or access environment variables containing sensitive configuration data such as database credentials or API keys.\nThe root cause is a failure to properly sanitize user-controlled input during the high-privilege administrative bootstrap process, effectively turning an onboarding feature into a vector for arbitrary code execution."
}