PatchSiren

payloadcms CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM payloadcms CVE published 2026-09-25

CVE-2026-93363

CVE-2026-93363 debrief based on the supplied source corpus. The CVE record was published on 2026-09-25T17:17:19.157Z and has not been modified since then. The @payloadcms/storage-vercel-blob storage adapter for Payload contains an improper access control vulnerability that allows authenticated users to bypass collection-level permissions by accessing the client-upload route directly. This vulnerability ha [truncated]