CVE-2026-105804
Description
Payload is a free and open source headless content management system. Payload versions from 3.0.0 before 3.90.0 and canary versions from 4.0.0-canary.0 before 4.0.0-canary.34 use a lower-than-recommended PBKDF2 work factor for password hashing, reducing the computational effort required to test recovered password hashes. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
Is your site exposed to CVE-2026-105804?
Run a free security scan — no signup, results in seconds.
Weakness Type (CWE)
References
Frequently Asked Questions
What is CVE-2026-105804? +
How do I check if I'm vulnerable to CVE-2026-105804? +
Related Vulnerabilities
TP-Link Deco M5 v1 uses a weak password hashing mechanism to store user credentials. An attacker who obtains the password …
A security issue exists within OTTO® Fleet Manager. The vulnerability stems from the use of an insufficient work factor in …
The administrative password is hashed using a comparatively weak, fast algorithm for the credential store backing one authentication path, and …
Windu CMS uses hashing algorithm based on MD5 and SHA1 with static salt to store user passwords. This allows an …
Use of Password Hash With Insufficient Computational Effort vulnerability in danielberkompas cloak_ecto and danielberkompas cloak allows an attacker who holds …
An attacker could exploit the 'Use of Password Hash With Insufficient Computational Effort' vulnerability in EveHome Eve Play to execute …