Impact
The flaw allows an attacker to send a request to a specific update endpoint that modifies collection documents without enforcing collection or field‑level authorization checks when the 'orderable' setting is enabled. This bypass reflects missing authorization controls (CWE‑639, CWE‑862) and lets an attacker arbitrarily change any data stored in those collections, potentially inserting malicious content or performing mass updates. No arbitrary code execution is required; the flaw is purely a data integrity issue.
Affected Systems
PayloadCMS installations running any public release older than 3.90.0, or any canary build older than 4.0.0‑canary.34, are affected. Those instances in which the 'orderable' feature is enabled on a collection or join field are vulnerable.
Risk and Exploitability
The CVSS score of 9.8 indicates a high severity. Because the exploit is remote and relies only on sending an HTTP request to the vulnerable update endpoint, it is practically exploitable for any installation where the ‘orderable’ option is enabled. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, but the lack of proper authorization controls (CWE‑639, CWE‑862) creates a significant risk of data integrity compromise.
OpenCVE Enrichment