← Blog · · df00tech

Payload CMS Patches Auth Token Field-Mapping Flaw (CVE-2026-105863)

breaking ghsa npm CVE-2026-105863

What happened

Payload CMS disclosed a GitHub Security Advisory (GHSA-66wr-7vmr-p5jq, CVE-2026-105863) describing an issue in how authentication tokens are issued at login. Under certain field configurations, Payload could include unintended values in the authentication token when a custom field option maps a field to a reserved authentication claim name. Payload has released patches restricting which field configuration options can influence token contents, and the advisory lists a public PoC as available. There is no complete workaround — the fix requires upgrading.

Why it matters for defenders

Payload is a widely used headless CMS, and authentication tokens are a core trust boundary — if unintended values can land in reserved claims, that could affect authorization decisions downstream depending on how an application consumes the token. The affected population is any deployment on an affected Payload version that uses a custom field configuration mapping a field to a reserved auth claim name. With a PoC already public, time-to-exploit is compressed, and teams running customized Payload instances should treat this as a priority patch item rather than routine maintenance.

What defenders should watch for now

  • Inventory all Payload CMS deployments and identify custom field configurations that map fields to reserved authentication claim names.
  • Upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34 as soon as possible — no interim mitigation exists.
  • Review authentication logs for anomalous token claims or unexpected privilege/role values associated with login events, as a general hunting angle while patching is rolled out.
  • Audit any custom field-to-claim mappings in your Payload configuration as part of post-patch verification.

Developing intel

This is a same-day advisory and details may evolve as the community analyzes the public PoC. No exploitation in the wild or ransomware use has been reported at this time. See the original GitHub Security Advisory for authoritative details: GHSA-66wr-7vmr-p5jq.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.