DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-105804: CVE-2026-105804: Insecure Default PBKDF2 Password Hashing Configuration in Payload CMS

CVE-2026-105804: Insecure Default PBKDF2 Password Hashing Configuration in Payload CMS

Vulnerability ID: CVE-2026-105804
CVSS Score: 5.7
Published: 2026-10-06

Payload CMS was discovered to use an insecure default configuration for its password-hashing mechanism. The system requested a 512-byte key from PBKDF2-HMAC-SHA256 with 25,000 iterations, creating a severe cryptographic asymmetry. While the defending server sequentially computed 16 blocks of key material (equivalent to 400,000 internal iterations), an offline attacker only needed to compute the first 32-byte block to verify password guesses. This allowed offline attackers to crack stolen database hashes 16 times faster than intended by the security design.

TL;DR

Payload CMS utilized a PBKDF2 configuration that requested a 512-byte output length. Because SHA-256 produces 32-byte blocks, the server performed 16x more work than necessary, whereas offline attackers could skip 15 of those blocks to verify guesses, granting them a 16x speedup advantage.


Technical Details

  • CWE ID: CWE-916
  • Attack Vector: Local
  • CVSS v4 Score: 5.7 (Medium)
  • EPSS Score: Not listed
  • Exploit Status: none
  • CISA KEV Status: Not Listed

Affected Systems

  • Payload CMS (payload) installations between versions 3.0.0 and 3.90.0
  • payload: >= 3.0.0, < 3.90.0 (Fixed in: 3.90.0)
  • payload: >= 4.0.0-canary.0, < 4.0.0-canary.34 (Fixed in: 4.0.0-canary.34)

Code Analysis

Commit: 1bc76e5

Fix insecure default password-hashing configuration and implement opportunistic prefix upgrade logic

Mitigation Strategies

  • Upgrade Payload CMS dependencies to patched versions immediately.
  • Enforce strict multi-factor authentication (MFA) to minimize the impact of cracked credentials.
  • Ensure robust access controls and encryption on database backups.

Remediation Steps:

  1. Update package.json dependencies to target payload versions >= 3.90.0.
  2. Run the package manager update command (e.g., npm update payload or yarn upgrade payload).
  3. Deploy the updated application to production environments.
  4. Monitor application logs for successful opportunistic password upgrades during user sign-ins.

References


Read the full report for CVE-2026-105804 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)