CVE-2026-105804: CVE-2026-105804: Insecure Default PBKDF2 Password Hashing Configuration in Payload CMS
CVE-2026-105804: Insecure Default PBKDF2 Password Hashing Configuration in Payload CMS Vulnerability ID: CVE-2026-105804 CVSS Score: 5.7 Published: 2026-10-06 Payload CMS was discovered to use an insecure default co
CVE-2026-105804: Insecure Default PBKDF2 Password Hashing Configuration in Payload CMS
Vulnerability ID: CVE-2026-105804
CVSS Score: 5.7
Published: 2026-10-06
Payload CMS was discovered to use an insecure default configuration for its password-hashing mechanism. The system requested a 512-byte key from PBKDF2-HMAC-SHA256 with 25,000 iterations, creating a severe cryptographic asymmetry. While the defending server sequentially computed 16 blocks of key material (equivalent to 400,000 internal iterations), an offline attacker only needed to compute the first 32-byte block to verify password guesses. This allowed offline attackers to crack stolen database hashes 16 times faster than intended by the security design.
TL;DR
Payload CMS utilized a PBKDF2 configuration that requested a 512-byte output length. Because SHA-256 produces 32-byte blocks, the server performed 16x more work than necessary, whereas offline attackers could skip 15 of those blocks to verify guesses, granting them a 16x speedup advantage.
Technical Details
- CWE ID: CWE-916
- Attack Vector: Local
- CVSS v4 Score: 5.7 (Medium)
- EPSS Score: Not listed
- Exploit Status: none
- CISA KEV Status: Not Listed
Affected Systems
- Payload CMS (payload) installations between versions 3.0.0 and 3.90.0
-
payload: >= 3.0.0, < 3.90.0 (Fixed in:
3.90.0) -
payload: >= 4.0.0-canary.0, < 4.0.0-canary.34 (Fixed in:
4.0.0-canary.34)
Code Analysis
Commit: 1bc76e5
Fix insecure default password-hashing configuration and implement opportunistic prefix upgrade logic
Mitigation Strategies
- Upgrade Payload CMS dependencies to patched versions immediately.
- Enforce strict multi-factor authentication (MFA) to minimize the impact of cracked credentials.
- Ensure robust access controls and encryption on database backups.
Remediation Steps:
- Update package.json dependencies to target payload versions >= 3.90.0.
- Run the package manager update command (e.g., npm update payload or yarn upgrade payload).
- Deploy the updated application to production environments.
- Monitor application logs for successful opportunistic password upgrades during user sign-ins.
References
Read the full report for CVE-2026-105804 on our website for more details including interactive diagrams and full exploit analysis.
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.