An authenticated user could overwrite an existing S3 object belonging to another upload collection, bypassing that collection’s access controls and prior file validation.
You are affected if ALL of these are true:
false.Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.
Disable client uploads until you can upgrade.
{
"cwe_ids": [
"CWE-639"
],
"github_reviewed": true,
"github_reviewed_at": "2026-10-07T20:28:59Z",
"nvd_published_at": "2026-10-06T17:17:23Z",
"severity": "HIGH"
}