CVE-2026-105858: Payload: Remote Code Execution through first-register
Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, a crafted request to the public first-register operation can execute code remotely when local authentication is enabled and no initial user has been created. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Payloadto a version that resolves this vulnerability.Fixed in 3.90.0 - Upgrade
Upgrade
Payloadto a version that resolves this vulnerability.Fixed in 4.0.0-canary.34
Event History
Frequently Asked Questions
Which deployments are exposed?
Payload CMS deployments are exposed if local authentication is enabled and no initial user has been created, provided they run a version before 3.90.0 or a canary version before 4.0.0-canary.34.
Does an attacker need credentials or user interaction?
No. The vector is network-based, requires no privileges, and requires no user interaction, although successful exploitation depends on access to the public first-register operation under the affected conditions.
What should teams do if they cannot patch immediately?
Prevent public access to the first-register operation until an initial user has been created, and ensure the affected deployment conditions are removed. The available fixes are 3.90.0 and 4.0.0-canary.34.
How can we determine whether an instance needs urgent remediation?
Check whether the instance is running a release before 3.90.0, or a canary release before 4.0.0-canary.34, and whether local authentication is enabled with no initial user created. Instances meeting all of those conditions should be treated as affected.