CVE-2026-105865 - Payload: Incomplete validation during the upload file lifecycle
CVE ID :CVE-2026-105865 Published : Oct. 6, 2026, 4:45 p.m. | 43 minutes ago Description :Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, an authenticated user who can update or delete uploads stored...