Payload: Field-level write access bypass in Payload on MongoDB
🔗 CVE IDs covered (1)
📋 Description
Impact
A vulnerability in field-level access control could allow an authenticated user to modify fields they are not permitted to change on documents they can otherwise update.
You are affected if:
Payload version < 3.87.0 (or a 4.0.0-canary release before 4.0.0-canary.20) using the MongoDB adapter (@payloadcms/db-mongodb) with any collection that relies on field-level access control to restrict writes under certain conditions.
Relational adapters (Postgres, SQLite) are not affected.
Patches
Handling of incoming field data has been hardened so field-level access control is enforced consistently.
Users should upgrade to 3.87.0 (or 4.0.0-canary.20 on the 4.x line) or later.
Workarounds
There is no complete workaround. Upgrading to 3.87.0 (or 4.0.0-canary.20 on the 4.x line) is recommended.
🎯 Affected products2
- npm/@payloadcms/db-mongodb:< 3.87.0
- npm/@payloadcms/db-mongodb:>= 4.0.0-canary.0, < 4.0.0-canary.20
🔗 References (6)
- https://github.com/payloadcms/payload/security/advisories/GHSA-4ww4-68q3-h7g5
- https://nvd.nist.gov/vuln/detail/CVE-2026-106100
- https://github.com/payloadcms/payload/commit/2a69863deb0e3c87e36c1b3b17ab2d5b02fcb941
- https://github.com/payloadcms/payload/commit/8f77dffa9552885ec2710768cfee15b57e389935
- https://github.com/payloadcms/payload/releases/tag/v3.87.0
- https://github.com/advisories/GHSA-4ww4-68q3-h7g5