๐Ÿ” CVE Alert

CVE-2026-106100

HIGH 7.1

Payload: Field-level write access bypass in Payload on MongoDB

CVSS Score
7.1
EPSS Score
0.0%
EPSS Percentile
0th

Payload is a free and open source headless content management system. In @payloadcms/db-mongodb versions before 3.87.0 and canary versions before 4.0.0-canary.20, an authenticated user who can update a document can modify fields that field-level write access control does not permit that user to change. The Postgres and SQLite adapters are not affected. This issue is fixed in versions 3.87.0 and 4.0.0-canary.20.

CWE CWE-639 CWE-915
Vendor payloadcms
Product payload
Published Oct 6, 2026
Last Updated Oct 6, 2026
Stay Ahead of the Next One

Get instant alerts for payloadcms payload

Be the first to know when new high vulnerabilities affecting payloadcms payload are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
High
Availability
None

Affected Versions

payloadcms / payload
< 3.87.0 >= 4.0.0-canary.0, < 4.0.0-canary.20

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/payloadcms/payload/security/advisories/GHSA-4ww4-68q3-h7g5 github.com: https://github.com/payloadcms/payload/commit/2a69863deb0e3c87e36c1b3b17ab2d5b02fcb941 github.com: https://github.com/payloadcms/payload/commit/8f77dffa9552885ec2710768cfee15b57e389935 github.com: https://github.com/payloadcms/payload/releases/tag/v3.87.0