GHSA-7c34-32v3-j575Medium

Payload relationship-query authorization bypass

Published
October 6, 2026
Last Modified
October 6, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact

A readable collection could expose information about protected documents in a related collection.

You are affected if:

  • You expose a readable collection with a relationship to a collection protected by access.read where constraints.

Patches

Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.

Workarounds

There is no complete workaround. Upgrade Payload packages >= 3.90.0 or >= 4.0.0-canary.34.

🎯 Affected products2

  • npm/payload:< 3.90.0
  • npm/payload:>= 4.0.0-canary.0, < 4.0.0-canary.34

🔗 References (4)