Vulnerability GHSA-4ww4-68q3-h7g5

High Risk
HIGH RISK
CVSS Score: 7.1
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
2 hours ago
October 07, 2026 at 04:19 PM UTC
Payload: Field-level write access bypass in Payload on MongoDB
1.0.0-beta.0 - 3.86.0 and 4.0.0-canary.0 - 4.0.0-canary.19
1.0.0-beta.0 - 3.86.0 and 4.0.0-canary.0 - 4.0.0-canary.19

Summary

Payload: Field-level write access bypass in Payload on MongoDB

Details

Impact

A vulnerability in field-level access control could allow an authenticated user to modify fields they are not permitted to change on documents they can otherwise update.

You are affected if: Payload version < 3.87.0 (or a 4.0.0-canary release before 4.0.0-canary.20) using the MongoDB adapter (@payloadcms/db-mongodb) with any collection that relies on field-level access control to restrict writes under certain conditions.

Relational adapters (Postgres, SQLite) are not affected.

Patches

Handling of incoming field data has been hardened so field-level access control is enforced consistently.

Users should upgrade to 3.87.0 (or 4.0.0-canary.20 on the 4.x line) or later.

Workarounds

There is no complete workaround. Upgrading to 3.87.0 (or 4.0.0-canary.20 on the 4.x line) is recommended.

Impacted packages

Timeline

Published
2 hours ago
October 07, 2026 at 04:19 PM UTC
Fixed (4.0.0-canary.20)
2 months ago
July 31, 2026 at 04:07 PM UTC
Fixed (3.87.0)
2 months ago
July 31, 2026 at 04:12 PM UTC
Last Modified
2 hours ago
October 07, 2026 at 04:30 PM UTC