Field-Level Access Control Issue in Payload CMS by Payload
CVE-2026-106100

7.1HIGH

Key Information:

Vendor

Payloadcms

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-106100?

In Payload CMS, specifically in the MongoDB adapter, an issue allows authenticated users to bypass field-level write access controls when updating documents. This vulnerability is present in versions before 3.87.0 and the canary versions prior to 4.0.0-canary.20. The allowed modifications could enable users to alter sensitive fields that should be restricted, posing a significant risk. This issue does not affect Postgres and SQLite adapters, and has been resolved in the latest versions.

Affected Version(s)

payload < 3.87.0 < 3.87.0

payload >= 4.0.0-canary.0, < 4.0.0-canary.20 < 4.0.0-canary.0, 4.0.0-canary.20

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.