Sceawere
Vulnerability Detail
CVE-2026-106100UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Payload MongoDB Access Control Bypass
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.1
- Creation Date
- 8h ago
- Vendor
- payloadcms
- Product
- payload
- Attack Type
- CWE-639: Authorization Bypass Through User-Controlled Key
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Payload is a free and open source headless content management system. In @payloadcms/db-mongodb versions before 3.87.0 and canary versions before 4.0.0-canary.20, an authenticated user who can update a document can modify fields that field-level write access control does not permit that user to change. The Postgres and SQLite adapters are not affected. This issue is fixed in versions 3.87.0 and 4.0.0-canary.20.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.1",
"pubDate": "2026-10-06T17:17:23.957Z",
"pubdate": "2026-10-06T17:17:23.957Z",
"executiveSummary": "The vulnerability constitutes an improper access control flaw within the @payloadcms/db-mongodb adapter of the Payload headless CMS. This security defect allows an authenticated user, who possesses the requisite permissions to perform document update operations, to circumvent field-level access control policies. Consequently, an attacker can modify restricted fields that are explicitly designated as protected by the CMS configuration. The vulnerability specifically affects the MongoDB adapter, while the Postgres and SQLite adapters remain unaffected. The risk is significant as it undermines the integrity of the data model and the security boundary enforced by the CMS's internal access control layer. Exploitation requires an authenticated session with existing document update privileges, enabling malicious actors to perform unauthorized data modifications that the application logic should otherwise block. Immediate patching is required to restore enforced field-level security.",
"technicalDetails": "The root cause of this vulnerability lies in the implementation of the @payloadcms/db-mongodb adapter's update logic, which fails to properly honor field-level write permissions when processing document updates. Within the Payload CMS architecture, access control is managed by a middleware and engine layer that evaluates configuration-based restrictions before persisting data to the underlying database. In the affected versions, the MongoDB adapter logic incorrectly processes update requests, bypassing the evaluation of access control definitions for specific document fields during the persistence phase.\nAffected versions include all iterations of @payloadcms/db-mongodb prior to 3.87.0 and canary versions before 4.0.0-canary.20. The vulnerability is exclusive to the MongoDB implementation, likely due to how update operations (e.g., $set, $push, etc.) are translated into native MongoDB driver queries without verifying individual field accessibility against the user's role and permission scope.\nThe attack flow proceeds as follows: First, an authenticated attacker with a legitimate 'update' privilege for a collection initiates a PUT or PATCH request to the Payload API. The request payload includes both permitted fields and one or more protected fields that the user is not authorized to edit. Under normal operation, the CMS should strip or reject updates to these sensitive fields. However, due to the flawed adapter logic, the MongoDB adapter applies the update operation to the entire document object without filtering or validating field-level restrictions. As a result, the database records are mutated with the prohibited data.\nBecause the vulnerability operates at the database adapter level, it successfully bypasses the abstraction layer meant to enforce security policies. The impact is a breach of confidentiality and integrity regarding protected document fields. An attacker could potentially escalate privileges, modify internal system metadata, or corrupt sensitive application data by overwriting fields protected by field-level access controls. This vulnerability does not require complex reconnaissance, as it relies on the direct manipulation of API requests to trigger the flawed logic within the adapter's update function."
}