Where
-Infinity
0
Severity
6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Impact

An unauthenticated attacker who knows an account’s email address or username could trigger Payload’s account lockout mechanism and prevent that user from signing in.

You are affected if:

Using an affected Payload version with an auth-enabled collection that uses local authentication and account lockout.

Applications that do not use Payload local authentication are not affected.

Patches

Successful password resets now clear the account’s lockout state. The forgot-password flow also enforces a configurable minimum interval between reset emails, which defaults to 15 seconds.

Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.

1 / 2
Source: GitHub
First published (updated )
Severity
9.2
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Impact

Under certain field configurations, Payload could include unintended values in the authentication token issued at login.

You are affected if:

- You use an affected Payload version and have configured a custom field option that maps a field to a reserved authentication claim name.

Patches Payload now restricts which field configuration options can influence the contents of the authentication token.

Users should upgrade payload packages to >= 3.90.0 or >= 4.0.0-canary.34.

Workarounds There is no complete workaround. Users should upgrade payload packages to >= 3.90.0 or >= 4.0.0-canary.34.

1 / 2
Source: GitHub
First published (updated )
Severity
7.2
Infoleak
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Impact

Under certain external upload configurations, Payload could send authentication data to a destination that was not verified as trusted. If the affected request contained a valid session, this could expose that session to an unintended recipient.

You are affected if:

- You have enabled external URL-based upload retrieval, where authenticated requests can trigger it.

Patches

Payload now validates the destination before forwarding authentication data and reapplies that validation when a request changes destination.

Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.

Workarounds It is recommended to update all Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.

If you cannot, a valid workaround exists: - Disable external URL-based upload retrieval where practical. - If you cannot disable it, configure the upload header filter to remove authentication data from outbound file requests. - Restrict access to the affected upload functionality.

1 / 2
Source: GitHub
First published (updated )
Severity
9.8
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Impact

An attacker can submit a request to a specific endpoint that permits collection documents to be updated regardless of access control and field level access control.

You are affected if:

- You are configuring orderable: true with any collection or join field.

Patches

In the patched version access control is properly enforced.

Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.

1 / 2
Source: GitHub
First published (updated )
Severity
7.6
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Impact

When an auth collection defined a field-level access.update restriction on the password field, the restriction was not enforced on the server correctly.

Patches

Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.

1 / 2
Source: GitHub
First published (updated )
Severity
7.1
Infoleak
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Impact

Token refresh and password reset responses could return fields that the requesting user did not have access to.

You are affected if:

- An authentication collection contains hidden or read-restricted fields.

Patches

Authentication responses now apply field access and hidden-field filtering before returning user documents. Full user documents remain available server-side for access control.

Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.

Custom authentication strategies remain responsible for filtering user documents returned through custom responses.

Workarounds

There is no complete workaround. Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.

1 / 2
Source: GitHub
First published (updated )
Severity
7.7
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Impact

Users with read access to other user documents could access their active API keys. An exposed key grants the target account’s permissions until rotated or disabled.

You are affected if:

- An authentication collection enables useAPIKey. - Users have read access to other user documents containing active API keys.

Patches

Users should upgrade payload packages to >= 3.90.0 or >= 4.0.0-canary.34.

Workarounds

Disable useAPIKey or restrict users to reading only their own authentication document. Rotate any API key that may have been exposed.

1 / 2
Source: GitHub
First published (updated )
Severity
9.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Impact An unauthenticated user could cause unintended application behavior when the Import Export plugin is enabled, allowing an attacker to submit and execute remote code (RCE).

Applications that do not use @payloadcms/plugin-import-export are not affected.

Patches Users should upgrade Payload packages to >= 3.88.0 or >= 4.0.0-canary.27.

Workarounds Upgrading is recommended. Until then, disable the Import Export plugin or restrict access to its endpoints.

1 / 2
Source: GitHub
First published (updated )
Severity
6.9
Infoleak
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Impact Under certain conditions, sorting readable records could reveal limited information about fields the requester was not permitted to read.

You are affected if untrusted users can query a collection, control its sorting, and sort by protected fields.

Patches Payload now applies field-level access checks to sort fields before executing queries.

Users should upgrade to >= 3.88.0 or >= 4.0.0-canary.27.

Workarounds Upgrading is recommended. Until then, prevent untrusted users from controlling sort parameters or restrict their access to affected collections.

1 / 2
Source: GitHub
First published (updated )
Severity
5.7
CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Impact The password-hashing configuration used a lower work factor than what is recommended.

Patches Payload now uses stronger password-hashing parameters and transparently upgrades older hashes following a successful login.

Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.

Workarounds Upgrading is recommended. Until you can upgrade, protect database copies and backups from unauthorized access and require strong, unique passwords.

1 / 2
Source: GitHub
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203