Sceawere

Vulnerability Detail

CVE-2026-106100UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Payload MongoDB Access Control Bypass

Vulnerability Metadata

Severity
High
Score / CVSS
7.1
Creation Date
8h ago
Vendor
payloadcms
Product
payload
Attack Type
CWE-639: Authorization Bypass Through User-Controlled Key
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

Payload is a free and open source headless content management system. In @payloadcms/db-mongodb versions before 3.87.0 and canary versions before 4.0.0-canary.20, an authenticated user who can update a document can modify fields that field-level write access control does not permit that user to change. The Postgres and SQLite adapters are not affected. This issue is fixed in versions 3.87.0 and 4.0.0-canary.20.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.1",
  "pubDate": "2026-10-06T17:17:23.957Z",
  "pubdate": "2026-10-06T17:17:23.957Z",
  "executiveSummary": "The vulnerability constitutes an improper access control flaw within the @payloadcms/db-mongodb adapter of the Payload headless CMS. This security defect allows an authenticated user, who possesses the requisite permissions to perform document update operations, to circumvent field-level access control policies. Consequently, an attacker can modify restricted fields that are explicitly designated as protected by the CMS configuration. The vulnerability specifically affects the MongoDB adapter, while the Postgres and SQLite adapters remain unaffected. The risk is significant as it undermines the integrity of the data model and the security boundary enforced by the CMS's internal access control layer. Exploitation requires an authenticated session with existing document update privileges, enabling malicious actors to perform unauthorized data modifications that the application logic should otherwise block. Immediate patching is required to restore enforced field-level security.",
  "technicalDetails": "The root cause of this vulnerability lies in the implementation of the @payloadcms/db-mongodb adapter's update logic, which fails to properly honor field-level write permissions when processing document updates. Within the Payload CMS architecture, access control is managed by a middleware and engine layer that evaluates configuration-based restrictions before persisting data to the underlying database. In the affected versions, the MongoDB adapter logic incorrectly processes update requests, bypassing the evaluation of access control definitions for specific document fields during the persistence phase.\nAffected versions include all iterations of @payloadcms/db-mongodb prior to 3.87.0 and canary versions before 4.0.0-canary.20. The vulnerability is exclusive to the MongoDB implementation, likely due to how update operations (e.g., $set, $push, etc.) are translated into native MongoDB driver queries without verifying individual field accessibility against the user's role and permission scope.\nThe attack flow proceeds as follows: First, an authenticated attacker with a legitimate 'update' privilege for a collection initiates a PUT or PATCH request to the Payload API. The request payload includes both permitted fields and one or more protected fields that the user is not authorized to edit. Under normal operation, the CMS should strip or reject updates to these sensitive fields. However, due to the flawed adapter logic, the MongoDB adapter applies the update operation to the entire document object without filtering or validating field-level restrictions. As a result, the database records are mutated with the prohibited data.\nBecause the vulnerability operates at the database adapter level, it successfully bypasses the abstraction layer meant to enforce security policies. The impact is a breach of confidentiality and integrity regarding protected document fields. An attacker could potentially escalate privileges, modify internal system metadata, or corrupt sensitive application data by overwriting fields protected by field-level access controls. This vulnerability does not require complex reconnaissance, as it relies on the direct manipulation of API requests to trigger the flawed logic within the adapter's update function."
}
CVE-2026-106100: Payload MongoDB Access Control Bypass (HIGH Severity, CVSS: 7.1) | Sceawere