Payload, Unauthenticated account-lockout denial of service, CVE-2026-105866 (Moderate) -DC-Oct2026-2847

Listen to this Post

This security advisory addresses a critical denial of service vulnerability identified in Payload CMS affecting local authentication configurations. The flaw specifically resides in how authentication mechanisms handle excessive failed login attempts and state tracking for user accounts. An unauthenticated remote attacker who manages to obtain a valid target username or email address can deliberately transmit repeated incorrect authentication payloads to the application endpoint. Because the underlying system lacks proper rate-limiting restrictions and fails to invalidate or properly clear lockout states upon specific password reset triggers or interval checks, the attacker can programmatically lock out the targeted user. Consequently, legitimate users are entirely blocked from authenticating, signing into their dashboards, or accessing authorized resources. Successful exploitation disrupts application availability on a per-user basis without requiring any prior privileges or complex interaction, presenting a notable risk to service availability across vulnerable installations.

DailyCVE Form:

Platform: Payload CMS
Version: < 3.90.0
Vulnerability : Account-lockout DoS
Severity : Moderate
date: Sep 18, 2026

Prediction: Patched

What Undercode Say:

Analytics

Bash commands and codes:

npm install [email protected]
npm update payload

Exploit: (Educational Purposes!)

curl -X POST https://target-app.com/api/users/login \
-H "Content-Type: application/json" \
-d '{"email": "[email protected]", "password": "wrongpassword"}'

Protection: from this CVE

Upgrade Payload packages to version 3.90.0 or 4.0.0-canary.34 immediately. Ensure minimum reset intervals are configured properly and local authentication flows are actively monitored for automated lockout attempts.

Impact:

An unauthenticated attacker can arbitrarily lock out valid system users by knowing their email address or username, leading to persistent denial of service and preventing legitimate logins.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top