๐Ÿ” CVE Alert

CVE-2026-105851

UNKNOWN 0.0

Payload: Field access control bypass on auth collections

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Payload is a free and open source headless content management system. In versions from 3.0.0 before 3.90.0 and canary versions before 4.0.0-canary.34, the duplicate operation copies values from a source document even when a field is hidden or its access.read or access.create rule rejects that value for the caller. The disableDuplicate setting does not prevent this access-control bypass. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.

CWE CWE-284 CWE-863
Vendor payloadcms
Product payload
Published Oct 6, 2026
Stay Ahead of the Next One

Get instant alerts for payloadcms payload

Be the first to know when new unknown vulnerabilities affecting payloadcms payload are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

payloadcms / payload
> 3.0.0, < 3.90.0 > 4.0.0-canary.0, < 4.0.0-canary.34

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/payloadcms/payload/security/advisories/GHSA-vc4h-q48j-5hcx github.com: https://github.com/payloadcms/payload/commit/099ef12e2682f076aa8e8d0ccb790536b4e1027f github.com: https://github.com/payloadcms/payload/releases/tag/v3.90.0