OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2026-105858 (CVSS 8.1)

NVD · officialPublished Oct 6, 2026Risk 37/100

Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, a crafted request to the public first-register operation can execute code remotely when local authentication is enabled and no initial user has been created. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.

CVSS
8.1
AV:NetworkAC:HighPR:NoneUI:NoneC:HighI:HighA:High

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source