CVE-2026-105866 | Payload CMS up to 3.89.x Account Lockout Mechanism privileges management

SecurityVulns

A vulnerability categorized as problematic has been discovered in Payload CMS Payload up to 3.89.x. This issue affects some unknown processing of the component Account Lockout Mechanism. Executing a manipulation can lead to improper privilege management.

This vulnerability is tracked as CVE-2026-105866. The attack can be launched remotely. No exploit exists.

It is advisable to upgrade the affected component.VulDB Recent EntriesRead More