Payload, Client uploads S3 Object Overwrite, CVE-2026-105867 (High) -DC-Oct2026-2852

Listen to this Post

The vulnerability tracked as CVE-2026-105867 affects PayloadCMS in the storage-s3 package versions prior to 3.90.0 and canary versions before 4.0.0-canary.34. It arises when client-side file uploads are enabled across multiple distinct collections that share the exact same underlying S3 bucket, coupled with the configuration setting useCompositePrefixes being unset or explicitly set to false. Under these specific conditions, an authenticated malicious user can exploit the storage mapping behavior to target and overwrite pre-existing S3 objects belonging to entirely different upload collections. This critical flaw completely bypasses collection-level access restrictions, isolation boundaries, and prior file validation checks enforced by the application layer. Consequently, lower-privileged users can corrupt data, replace sensitive assets, or manipulate files across isolated namespaces within the shared cloud storage container. Remediation requires upgrading the affected packages immediately or ensuring composite prefixes are properly enabled.

DailyCVE Form:

Platform: PayloadCMS
Version: < 3.90.0
Vulnerability : S3 Overwrite
Severity: High
date: Oct 6, 2026

Prediction: Available Now

What Undercode Say

Exploit: (Educational Purposes!)

Target simulation via shared bucket client upload manipulation
curl -X POST "https://vulnerable-payload-app.com/api/uploads" \
-H "Authorization: Bearer <low-priv-token>" \
-F "[email protected];filename=shared-target-name.pdf"

Protection:

Upgrade Payload packages to version 3.90.0 or 4.0.0-canary.34, or temporarily disable client uploads and enable composite prefixes.

Impact:

Authenticated users can overwrite S3 objects belonging to other collections, bypassing access controls and validation checks.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top