Payload CMS, Open Redirect, CVE-2026-105846 (Moderate) -DC-Oct2026-2786

Listen to this Post

CVE-2026-105846 is a moderate-severity open redirect vulnerability affecting the Payload CMS authentication flow. The flaw resides in the `@payloadcms/next` package and the core `payload` package, where the application fails to properly validate the `redirect` URL parameter during the login process. When a guest user initiates authentication, the system accepts a user-supplied callback URL that determines where the user is sent after a successful login. In vulnerable versions, Payload CMS does not enforce a whitelist of trusted domains or restrict the redirect target to local paths, allowing an attacker to inject an arbitrary external URL into the authentication flow. Consequently, after the victim enters their credentials on the legitimate login page, the application redirects them to an attacker-controlled destination, such as a phishing site designed to harvest credentials or distribute malware. This vulnerability is classified as CWE-601: URL Redirection to Untrusted Site (‘Open Redirect’) and carries a CVSS 3.1 base score of 6.1, reflecting a network attack vector, low attack complexity, no privileges required, and required user interaction. The affected versions include `payload` from 3.40.0 before 3.88.0, and canary versions from 4.0.0-canary.0 before 4.0.0-canary.27; the `@payloadcms/next` package is affected from 3.31.0 before 3.88.0, and canary versions from 4.0.0-canary.0 before 4.0.0-canary.27. The patched versions are 3.88.0 and 4.0.0-canary.27, which enforce strict validation of redirect URLs. Exploitation relies on social engineering rather than technical sophistication, as an attacker only needs to craft a malicious link containing a redirect parameter pointing to an external domain. This makes the vulnerability a low-effort, high-impact threat for organizations using Payload CMS, particularly those with public-facing authentication endpoints. The operational impact centers on phishing campaigns, where users are more likely to trust URLs that maintain visual continuity with known services during the transition phase. Additionally, if session tokens or cookies are transmitted in the URL query string due to misconfigured redirect handling, sensitive authentication data could be leaked to third-party domains via HTTP Referer headers or browser history logging mechanisms. The root cause lies in how the application handles redirect parameters after a successful authentication attempt, failing to adequately validate these URLs against a whitelist of trusted domains. This behavior bypasses standard security controls that rely on domain verification, effectively turning the legitimate authentication flow into a vector for social engineering attacks.

DailyCVE Form:

Platform: Payload CMS
Version: 3.40.0-3.88.0
Vulnerability : Open Redirect
Severity: Moderate
date: 2026-10-06

Prediction: 2026-10-20

What Undercode Say:

Check Payload CMS version
npm list payload
Check @payloadcms/next version
npm list @payloadcms/next
Craft malicious redirect link
echo "https://target-payload-cms.com/admin/login?redirect=https://evil-phishing-site.com"
// Vulnerable redirect handling (simplified example)
const redirectUrl = req.query.redirect;
res.redirect(redirectUrl); // No validation applied

Exploit: (Educational Purposes!)

Step 1: Identify Payload CMS login endpoint
curl -s "https://target-payload-cms.com/admin/login" | grep -i "redirect"
Step 2: Craft malicious redirect parameter
MALICIOUS_URL="https://evil-phishing-site.com/login"
TARGET="https://target-payload-cms.com/admin/login?redirect=${MALICIOUS_URL}"
Step 3: Send crafted link to victim (social engineering)
echo "Send this link to victim: ${TARGET}"
Step 4: Victim authenticates and is redirected to malicious site
The victim's browser follows the redirect after successful login

Protection: from this CVE

Upgrade Payload CMS to patched version
npm install [email protected]
npm install @payloadcms/[email protected]
Or upgrade to canary patched version
npm install [email protected]
npm install @payloadcms/[email protected]
Workaround: Remove user-controlled redirect values
Validate redirect URLs against a whitelist of trusted domains
Restrict redirect targets to known local paths only

Impact: An attacker can craft a redirect link that sends a guest user to an untrusted destination after authenticating, enabling phishing attacks and potential credential harvesting.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top