Access Control Vulnerability in Payload CMS by Payload
CVE-2026-105859
9.8CRITICAL
What is CVE-2026-105859?
An access control vulnerability in Payload CMS allows attackers to submit requests to a specific update endpoint, enabling them to modify collection documents without appropriate collection or field-level access controls. This issue arises when the 'orderable' option is enabled on specific collections or join fields. Users are advised to update to versions 3.90.0 or 4.0.0-canary.34 to mitigate this risk.
Affected Version(s)
payload < 3.90.0 < 3.90.0
payload >= 4.0.0-canary.0, < 4.0.0-canary.34 < 4.0.0-canary.0, 4.0.0-canary.34
