OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2026-106100: Payload: Field-level write access bypass in Payload on MongoDB

GitHub Advisories · officialPublished Oct 7, 2026Risk 37/100

### Impact A vulnerability in field-level access control could allow an authenticated user to modify fields they are not permitted to change on documents they can otherwise update. You are affected if: Payload version < `3.87.0` (or a `4.0.0-canary` release before `4.0.0-canary.20`) using the MongoDB adapter (`@payloadcms/db-mongodb`) with any collection that relies on field-level access control to restrict writes under certain conditions. Relational adapters (Postgres, SQLite) are not affected. ### Patches Handling of incoming field data has been hardened so field-level access control is enforced consistently. Users should upgrade to `3.87.0` (or `4.0.0-canary.20` on the `4.x` line) or later. ### Workarounds There is no complete workaround. Upgrading to `3.87.0` (or `4.0.0-canary.20` on the `4.x` line) is recommended.

Upgrade affected packages to a patched version: @payloadcms/db-mongodb 3.87.0, @payloadcms/db-mongodb 4.0.0-canary.20.

Vendor
Not specified
Product
@payloadcms/db-mongodb
Exploitation
none known
Evidence
official
CVSS
7.1

This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source