CVE-2026-106100: Payload: Field-level write access bypass in Payload on MongoDB
### Impact A vulnerability in field-level access control could allow an authenticated user to modify fields they are not permitted to change on documents they can otherwise update. You are affected if: Payload version < `3.87.0` (or a `4.0.0-canary` release before `4.0.0-canary.20`) using the MongoDB adapter (`@payloadcms/db-mongodb`) with any collection that relies on field-level access control to restrict writes under certain conditions. Relational adapters (Postgres, SQLite) are not affected. ### Patches Handling of incoming field data has been hardened so field-level access control is enforced consistently. Users should upgrade to `3.87.0` (or `4.0.0-canary.20` on the `4.x` line) or later. ### Workarounds There is no complete workaround. Upgrading to `3.87.0` (or `4.0.0-canary.20` on the `4.x` line) is recommended.
Recommended action
Recommended action
Upgrade affected packages to a patched version: @payloadcms/db-mongodb 3.87.0, @payloadcms/db-mongodb 4.0.0-canary.20.
Technical details
- Vendor
- Not specified
- Product
- @payloadcms/db-mongodb
- Exploitation
- none known
- Evidence
- official
Evidence and sources
This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source