A vulnerability in field-level access control could allow an authenticated user to modify fields they are not permitted to change on documents they can otherwise update.
You are affected if:
Payload version < 3.87.0 (or a 4.0.0-canary release before 4.0.0-canary.20) using the MongoDB adapter (@payloadcms/db-mongodb) with any collection that relies on field-level access control to restrict writes under certain conditions.
Relational adapters (Postgres, SQLite) are not affected.
Handling of incoming field data has been hardened so field-level access control is enforced consistently.
Users should upgrade to 3.87.0 (or 4.0.0-canary.20 on the 4.x line) or later.
There is no complete workaround. Upgrading to 3.87.0 (or 4.0.0-canary.20 on the 4.x line) is recommended.
{
"cwe_ids": [
"CWE-639",
"CWE-915"
],
"github_reviewed": true,
"github_reviewed_at": "2026-10-07T16:19:57Z",
"nvd_published_at": "2026-10-06T17:17:23Z",
"severity": "HIGH"
}