Description
The @payloadcms/storage-vercel-blob storage adapter for Payload contains an improper access control vulnerability that allows authenticated users to bypass collection-level permissions by accessing the client-upload route directly. Attackers can upload files through the client-upload endpoint without possessing the required collection access permissions, circumventing the intended access control enforcement.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Fri, 25 Sep 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The @payloadcms/storage-vercel-blob storage adapter for Payload contains an improper access control vulnerability that allows authenticated users to bypass collection-level permissions by accessing the client-upload route directly. Attackers can upload files through the client-upload endpoint without possessing the required collection access permissions, circumventing the intended access control enforcement. | |
| Title | Payload CMS storage-vercel-blob Adapter Improper Access Control on Upload Route | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-25T17:08:24.978Z
Reserved: 2026-09-17T18:41:40.758Z
Link: CVE-2026-93363
No data.
Status : Received
Published: 2026-09-25T17:17:19.157
Modified: 2026-09-25T18:17:33.190
Link: CVE-2026-93363
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-862
Missing Authorization