AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-105851.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSCRITICAL / 9.3CVSS 4.0 · GitHub reviewed advisory
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSGitHub reviewed advisoryModified Oct 06, 2026

Disclosure summary

## Impact Payload's duplicate operation copies field values from the source document even when a field is hidden, or its `access.read` or `access.create` rule would reject the value for that caller. The `disableDuplicate` collection setting, enabled by default on auth collections, did not stop this. ## Patches Users should upgrade Payload packages to `>= 3.90.0` or `>= 4.0.0-canary.34`. ## Workarounds Add a beforeDuplicate field hook to fields and set the value to empty or your default value.

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-vc4h-q48j-5hcx

Open original source · Updated Oct 06, 2026

Payload: Field access control bypass on auth collections

Source severity: CRITICAL / 9.3

EcosystemPackageAffected rangeFirst patched
npmpayload> 3.0.0, < 3.90.03.90.0
npmpayload> 4.0.0-canary.0, < 4.0.0-canary.344.0.0-canary.34

Original records & references

PUBLISHED 2026-10-06T12:17:23-04:00
MODIFIED 2026-10-06T12:17:25-04:00
INGESTED 2026-10-08T12:05:11-04:00