Impact
A flaw in Payload’s MongoDB adapter allows an authenticated user with document update rights to alter fields that the field‑level write access control is meant to protect. This bypass could enable an attacker to inject malicious data, elevate privileges, or corrupt content, thereby compromising data integrity and potentially enabling further exploitation of the system.
Affected Systems
The issue exists in Payload CMS versions earlier than 3.87.0 and canary releases earlier than 4.0.0‑canary.20 when using the @payloadcms/db‑mongodb adapter. The Postgres and SQLite adapters are not affected.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity impact, while the EPSS score is unavailable and the vulnerability is not listed in the CISA KEV catalog. Because the attack requires authenticated access to the CMS, an insider or a compromised account can exploit the flaw. The potential consequences include unauthorized data modification, privilege escalation, and integrity loss, all of which could degrade the trustworthiness of the content system.
OpenCVE Enrichment