GHSA-jg8r-5jh2-v2xj

Suggest an improvement
Source
https://github.com/advisories/GHSA-jg8r-5jh2-v2xj
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-jg8r-5jh2-v2xj/GHSA-jg8r-5jh2-v2xj.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-jg8r-5jh2-v2xj
Aliases
Published
2026-06-26T18:33:59Z
Modified
2026-09-04T19:10:34Z
Severity
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Payload CMS default account-unlock access allows authenticated users to reset other accounts' lockouts
Details

An Improper Authorization vulnerability exists in PayloadCMS version 3.84.1 due to insufficient access control on the account unlock operation.

Database specific
{
    "cwe_ids":  [
        "CWE-307"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-09-04T17:47:16Z",
    "nvd_published_at":  "2026-06-26T17:16:32Z",
    "severity":  "MODERATE"
}
References

Affected packages

npm / payload

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
3.88.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-jg8r-5jh2-v2xj/GHSA-jg8r-5jh2-v2xj.json"