CVE-2026-105868 | Payload CMS up to 3.89.x Local Upload unrestricted upload
A vulnerability, which was classified as critical, has been found in Payload CMS Payload up to 3.89.x. Affected by this vulnerability is an unknown functionality of the component Local Upload. The manipulation leads to unrestricted upload.
This vulnerability is traded as CVE-2026-105868. It is possible to initiate the attack remotely. There is no exploit available.
It is advisable to upgrade the affected component.VulDB Recent EntriesRead More