GHSA-f7hx-52q9-hcrfCriticalCVSS 9.8

Payload: Unauthorized update to collection documents

Published
October 7, 2026
Last Modified
October 7, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact

An attacker can submit a request to a specific endpoint that permits collection documents to be updated regardless of access control and field level access control.

You are affected if:

  • You are configuring orderable: true with any collection or join field.

Patches

In the patched version access control is properly enforced.

Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.

🎯 Affected products2

  • npm/payload:< 3.90.0
  • npm/payload:>= 4.0.0-canary.0, < 4.0.0-canary.34

🔗 References (5)