CVE-2026-105846 | Payload CMS up to 3.87.x/4.0.0-canary.26 Authentication Flow redirect

SecurityVulns

A vulnerability was found in Payload CMS Payload up to 3.87.x/4.0.0-canary.26 and classified as problematic. This affects an unknown function of the component Authentication Flow. Executing a manipulation of the argument redirect can lead to open redirect.

The identification of this vulnerability is CVE-2026-105846. The attack may be launched remotely. There is no exploit available.

It is suggested to upgrade the affected component.VulDB Recent EntriesRead More