Dev.to Security 🔐 Cybersecurity 👁 0 📖 1 min read

CVE-2026-105804: CVE-2026-105804: Insecure Default PBKDF2 Password Hashing Configuration in Payload CMS

CVE-2026-105804: Insecure Default PBKDF2 Password Hashing Configuration in Payload CMS Vulnerability ID: CVE-2026-105804 CVSS Score: 5.7 Published: 2026-10-06 Payload CMS was discovered to use an insecure default co

CVE-2026-105804: Insecure Default PBKDF2 Password Hashing Configuration in Payload CMS

Vulnerability ID: CVE-2026-105804
CVSS Score: 5.7
Published: 2026-10-06

Payload CMS was discovered to use an insecure default configuration for its password-hashing mechanism. The system requested a 512-byte key from PBKDF2-HMAC-SHA256 with 25,000 iterations, creating a severe cryptographic asymmetry. While the defending server sequentially computed 16 blocks of key material (equivalent to 400,000 internal iterations), an offline attacker only needed to compute the first 32-byte block to verify password guesses. This allowed offline attackers to crack stolen database hashes 16 times faster than intended by the security design.

TL;DR

Payload CMS utilized a PBKDF2 configuration that requested a 512-byte output length. Because SHA-256 produces 32-byte blocks, the server performed 16x more work than necessary, whereas offline attackers could skip 15 of those blocks to verify guesses, granting them a 16x speedup advantage.

Technical Details

  • CWE ID: CWE-916
  • Attack Vector: Local
  • CVSS v4 Score: 5.7 (Medium)
  • EPSS Score: Not listed
  • Exploit Status: none
  • CISA KEV Status: Not Listed

Affected Systems

  • Payload CMS (payload) installations between versions 3.0.0 and 3.90.0
  • payload: >= 3.0.0, < 3.90.0 (Fixed in: 3.90.0)
  • payload: >= 4.0.0-canary.0, < 4.0.0-canary.34 (Fixed in: 4.0.0-canary.34)

Code Analysis

Commit: 1bc76e5

Fix insecure default password-hashing configuration and implement opportunistic prefix upgrade logic

Mitigation Strategies

  • Upgrade Payload CMS dependencies to patched versions immediately.
  • Enforce strict multi-factor authentication (MFA) to minimize the impact of cracked credentials.
  • Ensure robust access controls and encryption on database backups.

Remediation Steps:

  1. Update package.json dependencies to target payload versions >= 3.90.0.
  2. Run the package manager update command (e.g., npm update payload or yarn upgrade payload).
  3. Deploy the updated application to production environments.
  4. Monitor application logs for successful opportunistic password upgrades during user sign-ins.

References

Read the full report for CVE-2026-105804 on our website for more details including interactive diagrams and full exploit analysis.

📰 Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.