Improper Access Control in Payload CMS Storage Adapter
CVE-2026-93363
5.3MEDIUM
What is CVE-2026-93363?
The Payload CMS storage Vercel blob storage adapter is vulnerable due to improper access control, which enables authenticated users to bypass the established collection-level permissions. By accessing the client-upload route directly, attackers can upload files without possessing the necessary permissions, effectively undermining the intended access control mechanisms. This vulnerability poses significant risks, as it allows unauthorized file uploads that could lead to further exploitation of the system.
Affected Version(s)
payload 3.25.0 < 3.90.0
payload 4.0.0-canary.0 < 4.0.0-canary.34
