
DailyCVE@dailycve
🔴 Payload, Trust Validation Issue, #CVE-2026-105861 (High) -DC-Oct2026-2856 https://dailycve.com/payload-trust-validation-issue-cve-2026-105861-high-dc-oct2026-2856/
0000019
239 followersView on X
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
Payload is a free and open source headless content management system. In versions after 3.0.0 and before 3.90.0, authenticated external URL-based upload retrieval can forward authentication data to a redirected destination that was not verified as trusted, potentially exposing a valid session to an unintended recipient. This issue is fixed in version 3.90.0.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
NONE

🔴 Payload, Trust Validation Issue, #CVE-2026-105861 (High) -DC-Oct2026-2856 https://dailycve.com/payload-trust-validation-issue-cve-2026-105861-high-dc-oct2026-2856/