Field-Level Access Control Issue in Payload CMS by Payload
CVE-2026-106100
7.1HIGH
What is CVE-2026-106100?
In Payload CMS, specifically in the MongoDB adapter, an issue allows authenticated users to bypass field-level write access controls when updating documents. This vulnerability is present in versions before 3.87.0 and the canary versions prior to 4.0.0-canary.20. The allowed modifications could enable users to alter sensitive fields that should be restricted, posing a significant risk. This issue does not affect Postgres and SQLite adapters, and has been resolved in the latest versions.
Affected Version(s)
payload < 3.87.0 < 3.87.0
payload >= 4.0.0-canary.0, < 4.0.0-canary.20 < 4.0.0-canary.0, 4.0.0-canary.20
