PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-106100 payloadcms CVE debrief

A vulnerability in field-level access control in Payload on MongoDB could allow an authenticated user to modify fields they are not permitted to change on documents they can otherwise update. This affects Payload versions before 3.87.0 or 4.0.0-canary.20 when using the MongoDB adapter with field-level access control. Upgrading to 3.87.0 or 4.0.0-canary.20 or later is recommended.

Vendor
payloadcms
Product
@payloadcms/db-mongodb
CVSS
HIGH 7.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-07
Original CVE updated
2026-10-07
Advisory published
2026-10-07
Advisory updated
2026-10-07

Who should care

Defenders responsible for Payload installations using the MongoDB adapter with field-level access control should assess exposure and prioritize upgrading to the patched versions. This includes operators, platform administrators, vulnerability management teams, and security teams who need to verify affected deployments, review configurations, and implement compensating controls if necessary.

Why it matters

Defenders should care about CVE-2026-106100 because it allows authenticated users to modify fields they are not permitted to change, potentially leading to unauthorized data modifications. This vulnerability affects Payload installations using the MongoDB adapter with field-level access control. Upgrading to the patched versions is recommended to prevent potential security consequences.

  • Potential unauthorized data modifications
  • Field-level access control bypass
  • Authenticated users may modify restricted fields
  • Requires verification of affected versions and configurations

Technical summary

The vulnerability allows an authenticated user to modify fields they are not permitted to change on documents they can otherwise update. This affects Payload versions before 3.87.0 or 4.0.0-canary.20 when using the MongoDB adapter with field-level access control. The issue arises from inconsistent enforcement of field-level access control, potentially leading to unauthorized data modifications. Upgrading to 3.87.0 or 4.0.0-canary.20 or later is recommended to prevent potential security consequences. Users should review and update field-level access control configurations to ensure consistent enforcement.

Defensive priority

Defenders should prioritize upgrading to the patched versions to prevent potential unauthorized data modifications.

Recommended defensive actions

  • Upgrade to Payload version 3.87.0 or 4.0.0-canary.20 or later
  • Review and update field-level access control configurations
  • Monitor for potential unauthorized data modifications
  • Verify affected Payload installations using the MongoDB adapter with field-level access control
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The vulnerability is described in the official CVE record and the source item from osv_dev. The CVE Program and NIST National Vulnerability Database have also provided information on this vulnerability.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-106100 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-106100

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-106100 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-106100

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Payload: Field-level write access bypass in Payload on MongoDB

    Unverified legacy reference

    URL: https://storage.googleapis.com/osv-vulnerabilities/npm/GHSA-4ww4-68q3-h7g5.json

    osv_dev

  • Source reference

    Unverified legacy reference

    URL: https://github.com/payloadcms/payload/security/advisories/GHSA-4ww4-68q3-h7g5

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/payloadcms/payload/commit/2a69863deb0e3c87e36c1b3b17ab2d5b02fcb941

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/payloadcms/payload/commit/8f77dffa9552885ec2710768cfee15b57e389935

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/payloadcms/payload

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/payloadcms/payload/releases/tag/v3.87.0

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.