External risk intelligence

Payload CMS Access Control Bypass Leading to Unauthorized Collection Modification

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-105859

Payload is a headless content management system. CMS platforms are commonly deployed as internet-facing web applications or API backends to serve content and manage data, making the update endpoints and overall application surface frequently reachable from the public internet in standard deployments.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This critical vulnerability in Payload, a headless content management system, allows unauthenticated attackers to modify data without proper access controls. The issue stems from an update endpoint that bypasses collection and field-level security when specific ordering features are enabled. This could potentially lead to unauthorized data changes.

  • Unauthenticated access can alter data records.
  • Important for systems managing content or data.
  • Verify if your systems use this software.

Attack Path

How an attacker could exploit the issue

An attacker can reach a specific update endpoint in Payload if it's exposed externally, bypassing access controls to modify collection documents. This occurs when the "orderable" feature is enabled, allowing an unauthenticated attacker to potentially alter data.

  • No authentication required.
  • Submit a request to the update endpoint.
  • Unauthorized data modification.

Live Threat

Current exploitation, exposure, and threat context

An attacker could modify collection documents without proper access controls when the orderable setting is enabled on collection or join fields in Payload, a headless content management system. This could allow unauthorized changes to sensitive system or user data managed by the CMS.

  • Collection documents could be altered.
  • An attacker submits a request to a specific endpoint.
  • Unauthorized data modification of CMS content.

Operational Fix

Recommended remediation, mitigation, and detection steps

Platform teams and application owners are likely responsible for addressing this vulnerability in the Payload CMS. The first practical step is to identify all instances of Payload, determine their business criticality and external reachability, and then assign ownership for remediation planning.

  • Identify Payload instances and owners.
  • Verify public exposure and business impact.
  • Plan and coordinate remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Payload CMS?

Payload is a free, open-source headless content management system. Unlike traditional CMS platforms that bundle frontend templates, Payload functions as an API-first backend. Developers use it to manage data structures and content, which are then served to various applications—such as websites or mobile apps—through its interface.

What does CVE-2026-105859 mean?

This CVE refers to a vulnerability where access controls are incorrectly skipped. Specifically, it involves Improper Authorization (CWE-862) and Authorization Bypass (CWE-639). It means that when certain collection or field settings are active, the system fails to check if a user has permission to change data, allowing unauthorized modifications.

How can an attacker trigger this vulnerability?

An attacker triggers this by sending a request to a specific update endpoint within the CMS. The flaw only activates when the 'orderable' feature is enabled on a collection or join field. If 'orderable' is disabled for your collections, this specific bypass path is not present.

Is my Payload CMS instance at risk?

According to Halo Surface Signal, Payload instances are frequently deployed as internet-facing API backends, which increases the likelihood that an attacker can reach the vulnerable endpoint. If your instance is accessible from the public internet, it faces a higher risk of exploitation compared to those kept on internal, restricted networks.

Do I need to update my software?

Yes. The first step is to audit your environment to identify all running instances of Payload. Once identified, plan an upgrade to version 3.90.0 or 4.0.0-canary.34, which contain the security fixes. Coordinate with your team to verify which instances utilize the 'orderable' feature to prioritize your patching schedule.

References