PatchSiren cyber security CVE debrief
CVE-2026-106100 payloadcms CVE debrief
A vulnerability in field-level access control in Payload on MongoDB could allow an authenticated user to modify fields they are not permitted to change on documents they can otherwise update. This affects Payload versions before 3.87.0 or 4.0.0-canary.20 when using the MongoDB adapter with field-level access control. Upgrading to 3.87.0 or 4.0.0-canary.20 or later is recommended.
- Vendor
- payloadcms
- Product
- @payloadcms/db-mongodb
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-07
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-07
- Advisory updated
- 2026-10-07
Who should care
Defenders responsible for Payload installations using the MongoDB adapter with field-level access control should assess exposure and prioritize upgrading to the patched versions. This includes operators, platform administrators, vulnerability management teams, and security teams who need to verify affected deployments, review configurations, and implement compensating controls if necessary.
Why it matters
Defenders should care about CVE-2026-106100 because it allows authenticated users to modify fields they are not permitted to change, potentially leading to unauthorized data modifications. This vulnerability affects Payload installations using the MongoDB adapter with field-level access control. Upgrading to the patched versions is recommended to prevent potential security consequences.
- Potential unauthorized data modifications
- Field-level access control bypass
- Authenticated users may modify restricted fields
- Requires verification of affected versions and configurations
Technical summary
The vulnerability allows an authenticated user to modify fields they are not permitted to change on documents they can otherwise update. This affects Payload versions before 3.87.0 or 4.0.0-canary.20 when using the MongoDB adapter with field-level access control. The issue arises from inconsistent enforcement of field-level access control, potentially leading to unauthorized data modifications. Upgrading to 3.87.0 or 4.0.0-canary.20 or later is recommended to prevent potential security consequences. Users should review and update field-level access control configurations to ensure consistent enforcement.
Defensive priority
Defenders should prioritize upgrading to the patched versions to prevent potential unauthorized data modifications.
Recommended defensive actions
- Upgrade to Payload version 3.87.0 or 4.0.0-canary.20 or later
- Review and update field-level access control configurations
- Monitor for potential unauthorized data modifications
- Verify affected Payload installations using the MongoDB adapter with field-level access control
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The vulnerability is described in the official CVE record and the source item from osv_dev. The CVE Program and NIST National Vulnerability Database have also provided information on this vulnerability.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-106100 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-106100
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-106100 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-106100
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Payload: Field-level write access bypass in Payload on MongoDB
Unverified legacy reference
URL: https://storage.googleapis.com/osv-vulnerabilities/npm/GHSA-4ww4-68q3-h7g5.json
osv_dev
-
Source reference
Unverified legacy reference
URL: https://github.com/payloadcms/payload/security/advisories/GHSA-4ww4-68q3-h7g5
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/payloadcms/payload/commit/2a69863deb0e3c87e36c1b3b17ab2d5b02fcb941
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/payloadcms/payload/commit/8f77dffa9552885ec2710768cfee15b57e389935
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/payloadcms/payload
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/payloadcms/payload/releases/tag/v3.87.0
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.