CVE-2026-93363

Summary

The @payloadcms/storage-vercel-blob storage adapter for Payload contains an improper access control vulnerability that allows authenticated users to bypass collection-level permissions by accessing the client-upload route directly. Attackers can upload files through the client-upload endpoint without possessing the required collection access permissions, circumventing the intended access control enforcement.

Affected Software

VendorProductVersion RangeStatus
payloadcmspayload3.25.0 < 3.90.0affected
payloadcmspayload4.0.0-canary.0 < 4.0.0-canary.34affected

Weaknesses

  • CWE-862: Missing Authorization

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References