CVE-2026-93363
5.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Summary
The @payloadcms/storage-vercel-blob storage adapter for Payload contains an improper access control vulnerability that allows authenticated users to bypass collection-level permissions by accessing the client-upload route directly. Attackers can upload files through the client-upload endpoint without possessing the required collection access permissions, circumventing the intended access control enforcement.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| payloadcms | payload | 3.25.0 < 3.90.0 | affected |
| payloadcms | payload | 4.0.0-canary.0 < 4.0.0-canary.34 | affected |
Weaknesses
- CWE-862: Missing Authorization
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: partial
References
- https://github.com/payloadcms/payload/security/advisories/GHSA-mc8m-rr6c-r5qr
- https://www.vulncheck.com/advisories/payload-cms-storage-vercel-blob-adapter-improper-access-control-on-upload-route
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.