Payload CMS Import Export Plugin: Unauthenticated Prototype Pollution Leading to RCE (CVE-2026-105844)
What happened
A GitHub Security Advisory (GHSA-qf28-8hc6-vwrp), tracked as CVE-2026-105844, discloses a prototype pollution vulnerability in @payloadcms/plugin-import-export, a plugin for the Payload CMS. According to the advisory, an unauthenticated user can trigger unintended application behavior through this flaw, which the vendor states can be leveraged to submit and execute remote code (RCE). A public proof-of-concept is noted as available. Payload applications that do not have the Import Export plugin installed are not affected.
Why it matters for defenders
Unauthenticated RCE in a widely-used CMS plugin is a high-severity combination: no credentials are required, and successful exploitation could grant an attacker code execution on the hosting application server. Any organization running Payload CMS with the Import Export plugin enabled — commonly used for bulk data import/export in admin panels — should treat this as exposed attack surface, particularly on internet-facing deployments. No CVSS score has been published yet, but the vendor's own framing (unauthenticated + RCE) suggests critical severity.
What defenders should watch for or do now
- Inventory exposure: Identify any Payload CMS deployments and confirm whether
@payloadcms/plugin-import-exportis installed and enabled. - Patch or mitigate: The vendor recommends upgrading Payload to
>= 3.88.0or>= 4.0.0-canary.27. If immediate upgrade isn't feasible, disable the Import Export plugin or restrict network/access-control to its endpoints as an interim workaround. - Hunt for exploitation signs: Review web server and application logs for anomalous requests to import/export plugin endpoints, especially payloads attempting to manipulate object prototypes (e.g., keys like
__proto__,constructor, orprototypein request bodies). - Monitor for follow-on activity: Since the outcome is described as RCE, watch for unexpected child processes spawned by the Node.js application, outbound connections from the app server, or new/modified files consistent with webshell deployment.
Developing intel
This is a same-day advisory with limited public detail beyond the vendor's own description; no CVSS score or confirmed in-the-wild exploitation has been reported at this time, though a public PoC reportedly exists. We will continue to track this item as more information becomes available. For full technical details, see the original advisory: GHSA-qf28-8hc6-vwrp.