GHSA-f7hx-52q9-hcrfCriticalCVSS 9.8
Payload: Unauthorized update to collection documents
🔗 CVE IDs covered (1)
📋 Description
Impact
An attacker can submit a request to a specific endpoint that permits collection documents to be updated regardless of access control and field level access control.
You are affected if:
- You are configuring
orderable: truewith any collection or join field.
Patches
In the patched version access control is properly enforced.
Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.
🎯 Affected products2
- npm/payload:< 3.90.0
- npm/payload:>= 4.0.0-canary.0, < 4.0.0-canary.34
🔗 References (5)
- https://github.com/payloadcms/payload/security/advisories/GHSA-f7hx-52q9-hcrf
- https://nvd.nist.gov/vuln/detail/CVE-2026-105859
- https://github.com/payloadcms/payload/commit/36fa9af73dd04fa59f4b4a06d11454538c4c1409
- https://github.com/payloadcms/payload/releases/tag/v3.90.0
- https://github.com/advisories/GHSA-f7hx-52q9-hcrf