GHSA-4ww4-68q3-h7g5HighCVSS 7.1

Payload: Field-level write access bypass in Payload on MongoDB

Published
October 7, 2026
Last Modified
October 7, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact

A vulnerability in field-level access control could allow an authenticated user to modify fields they are not permitted to change on documents they can otherwise update.

You are affected if: Payload version < 3.87.0 (or a 4.0.0-canary release before 4.0.0-canary.20) using the MongoDB adapter (@payloadcms/db-mongodb) with any collection that relies on field-level access control to restrict writes under certain conditions.

Relational adapters (Postgres, SQLite) are not affected.

Patches

Handling of incoming field data has been hardened so field-level access control is enforced consistently.

Users should upgrade to 3.87.0 (or 4.0.0-canary.20 on the 4.x line) or later.

Workarounds

There is no complete workaround. Upgrading to 3.87.0 (or 4.0.0-canary.20 on the 4.x line) is recommended.

🎯 Affected products2

  • npm/@payloadcms/db-mongodb:< 3.87.0
  • npm/@payloadcms/db-mongodb:>= 4.0.0-canary.0, < 4.0.0-canary.20

🔗 References (6)