Vulnerability GHSA-fx49-4h83-wjv9

High Risk
HIGH RISK
CVSS Score: 8.0
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
1 hour ago
October 06, 2026 at 04:21 PM UTC
Payload didn't enforce field-level password update restrictions
0.1.137 - 3.89.0 and 4.0.0-canary.0 - 4.0.0-canary.33
0.1.137 - 3.89.0 and 4.0.0-canary.0 - 4.0.0-canary.33

Summary

Payload didn't enforce field-level password update restrictions

Details

Impact

When an auth collection defined a field-level access.update restriction on the password field, the restriction was not enforced on the server correctly.

Patches

Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.

Impacted packages

Timeline

Published
1 hour ago
October 06, 2026 at 04:21 PM UTC
Fixed (3.90.0)
Unknown
Unknown
Fixed (4.0.0-canary.34)
Unknown
Unknown
Last Modified
1 hour ago
October 06, 2026 at 04:30 PM UTC