Access Control Bypass in Payload CMS Versions 3.0.0 to 3.90.0
CVE-2026-105851

9.3CRITICAL

Key Information:

Vendor

Payloadcms

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-105851?

In certain versions of Payload CMS, an access control vulnerability exists where the duplicate operation can bypass restrictions and copy data from source documents that are intended to be hidden. This occurs even if the access.read or access.create rules reject the visibility of the data for the user making the request. The issue arises from the ineffective handling of the disableDuplicate setting, allowing unauthorized access to sensitive information. This flaw impacts versions released from 3.0.0 to anything prior to 3.90.0, alongside specific canary builds. An update to version 3.90.0 and 4.0.0-canary.34 resolves this issue.

Affected Version(s)

payload > 3.0.0, < 3.90.0 > 3.0.0, 3.90.0

payload > 4.0.0-canary.0, < 4.0.0-canary.34 > 4.0.0-canary.0, 4.0.0-canary.34

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.