Sceawere

Vulnerability Detail

CVE-2026-105859UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Payload CMS Unauthorized Document Modification

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
8h ago
Vendor
payloadcms
Product
payload
Attack Type
CWE-639: Authorization Bypass Through User-Controlled Key
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, an attacker can submit a request to a specific update endpoint that modifies collection documents without enforcing collection or field-level access control when orderable is enabled on a collection or join field. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-10-06T17:17:21.987Z",
  "pubdate": "2026-10-06T17:17:21.987Z",
  "executiveSummary": "A critical access control vulnerability exists in Payload CMS versions prior to 3.90.0 and 4.0.0-canary.34. The flaw resides in the handling of orderable fields within collection and join operations.\nThe vulnerability allows an unauthenticated or unauthorized attacker to submit requests to specific update endpoints, bypassing established collection-level and field-level access control policies.\nThe impact is significant, as it permits the unauthorized modification of collection documents, potentially leading to data manipulation, privilege escalation, or integrity compromise.\nExploitation requires the target system to have the orderable feature enabled on a collection or join field, which serves as the entry point for the bypass.\nThe risk implication is high, necessitating an immediate update to the patched versions to restore enforcement of security policies and protect the integrity of stored content.",
  "technicalDetails": "The root cause of this vulnerability is a failure in the Payload CMS access control middleware to validate user permissions when processing update requests specifically involving 'orderable' collection or join fields. In typical Payload configurations, access control hooks and policies are enforced during the document update pipeline; however, the logic governing the ordering update endpoint fails to verify these constraints before executing the database write operation.\nWhen a collection or join field is configured with the 'orderable' property, Payload exposes a dedicated endpoint or internal operation to handle the reordering of records. The vulnerability exists because the authorization check is omitted or improperly bypassed within the controller responsible for these ordering operations. Consequently, the application assumes that the incoming request is authorized, allowing the payload to modify the target document even if the requester lacks the appropriate 'update' permissions for the specific collection or fields being manipulated.\nThe attack flow proceeds as follows: First, an attacker identifies a target collection that utilizes the 'orderable' feature. Second, the attacker crafts a malicious request targeting the specific order-update endpoint of the Payload CMS API. Third, because the backend logic fails to verify the session's administrative or document-specific permissions during this specialized state transition, the application processes the request. Finally, the application updates the underlying database entry without performing the mandatory access control checks, effectively granting the attacker the ability to alter document states and orderings.\nThis behavior affects all Payload CMS instances running versions below 3.90.0 or 4.0.0-canary.34 that have collections with orderable fields enabled. The lack of privilege enforcement means that network-accessible instances are exposed, allowing any attacker capable of reaching the API to modify sensitive content. Post-exploitation impact includes the arbitrary manipulation of collection data, which can be leveraged to disrupt application functionality, reorder critical business logic assets, or potentially influence application workflows that rely on specific record sequences for security or authorization decisions."
}
CVE-2026-105859: Payload CMS Unauthorized Document Modification (CRITICAL Severity, CVSS: 9.8) | Sceawere