CVE-2026-105863

Status: Received

Description

Payload is a free and open source headless content management system. In versions after 3.0.0 and before 3.90.0, a custom field option that maps a field to a reserved authentication claim name can place unintended values in the authentication token issued at login. This issue is fixed in version 3.90.0.

Published
October 6, 2026 5:17 PM
Last Modified
October 6, 2026 5:17 PM
Source
[email protected]

Weaknesses (CWE)

CWE-290 CWE-915

References

Contact Us

Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.