Impact
The server fails to enforce a field‑level access.update restriction on the password field of the authentication collection, allowing any user who can send an update request to change another user’s password. This flaw enables unauthorized modification of authentication credentials and can lead to account takeover.
Affected Systems
Payload CMS (payloadcms:payload) is affected in all releases before version 3.90.0 and in canary builds before 4.0.0-canary.34. Users running these versions are at risk until the fix is applied by upgrading to the latest patch release.
Risk and Exploitability
The vulnerability is classified as Improper Access Control with a CVSS score of 7.6, indicating a high severity. An attacker only needs the ability to submit an update payload targeting the password field; no additional system access or privilege escalation is required. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog, but the high CVSS score still signifies a significant risk if left unresolved.
OpenCVE Enrichment
Github GHSA