External risk intelligence

Payload Import Export Plugin Remote Code Execution

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-105844

Payload is a content management system designed to serve web content and APIs. CMS platforms are commonly deployed as internet-facing web applications to enable public access to sites and administrative functions, making the vulnerable import/export plugin functionality accessible to remote network requests in typical production deployments.

Remote Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

An unauthenticated user can exploit a vulnerability in the import/export plugin of Payload, a content management system, to potentially execute arbitrary code on the system. This could allow an attacker to compromise the application and its underlying infrastructure if the plugin is enabled.

  • Unauthenticated users can exploit a plugin feature.
  • This could lead to remote code execution on systems.
  • Confirm relevance and exposure to Payload's import/export plugin.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can reach the vulnerable import/export plugin by submitting specially crafted data. This allows them to manipulate application behavior, potentially leading to remote code execution.

  • No authentication required.
  • Submit prototype-sensitive field paths.
  • Leads to remote code execution.

Live Threat

Current exploitation, exposure, and threat context

When the `@payloadcms/plugin-import-export` is enabled, an unauthenticated user could submit sensitive field paths that lead to unintended application behavior, potentially allowing for remote code execution. This could affect the integrity and availability of the Content Management System (CMS) and its hosted content.

  • CMS data and system integrity are at risk.
  • Unauthenticated network requests could exploit the plugin.
  • Remote code execution could compromise the CMS.

Operational Fix

Recommended remediation, mitigation, and detection steps

The affected technology is a headless CMS, suggesting that application owners and platform teams are most likely responsible for managing its security. The initial step involves identifying all instances of this CMS, confirming their network exposure and business criticality, and then locating the accountable owner to plan remediation.

  • Application owners should own the issue.
  • Verify affected instances are reachable.
  • Plan remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Payload and how is it used?

Payload is a free, open-source headless content management system. Developers use it to manage content via APIs, allowing them to build websites or applications where the backend is separated from the frontend. Because it serves as a central hub for data and administrative functions, it is often deployed to power web applications that require flexible content architecture.

What does CWE-1321 mean in the context of CVE-2026-105844?

This CVE involves a vulnerability known as Prototype Pollution, classified as CWE-1321. In plain English, it means the application fails to properly sanitize input, allowing an attacker to inject data that modifies the structure of underlying JavaScript objects. By changing these object prototypes, an attacker can manipulate how the application executes its own code, potentially resulting in unauthorized remote code execution.

How can an attacker trigger this vulnerability?

An unauthenticated user triggers the flaw by submitting specifically crafted, prototype-sensitive field paths to the system. The vulnerability is tied directly to the @payloadcms/plugin-import-export plugin; if this plugin is not enabled in your instance, the specific path used to exploit this weakness is not functional. It requires the plugin to be active to process the malicious input.

Is my system at risk if it runs Payload?

Halo Surface Signal indicates that because Payload is a content management system designed for web content and APIs, it is typically deployed as an internet-facing application. If your instance is reachable via the network and has the import/export plugin enabled, it is potentially accessible to remote requests from unauthenticated users, increasing the likelihood that it could be targeted.

How do I secure my installation against this CVE?

The first step is to verify whether your environment is running an affected version of Payload—specifically 3.0.0 through 3.87.x or certain canary versions before 4.0.0-canary.27. If you are using the import/export plugin, you should prioritize updating to version 3.88.0 or 4.0.0-canary.27, which contains the fix for this issue. Coordinate with your platform or development team to confirm if the plugin is in use.

References