CVE-2026-93363
EUVD-2026-8720625.09.2026, 17:17
The @payloadcms/storage-vercel-blob storage adapter for Payload contains an improper access control vulnerability that allows authenticated users to bypass collection-level permissions by accessing the client-upload route directly. Attackers can upload files through the client-upload endpoint without possessing the required collection access permissions, circumventing the intended access control enforcement.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| payloadcms | payload | 3.25.0 ≤ 𝑥 < 3.90.0 | CNA |
Common Weakness Enumeration