Advisories for Npm/@Payloadcms/Db-Mongodb package

2026

Payload: Field-level write access bypass in Payload on MongoDB

A vulnerability in field-level access control could allow an authenticated user to modify fields they are not permitted to change on documents they can otherwise update. You are affected if: Payload version < 3.87.0 (or a 4.0.0-canary release before 4.0.0-canary.20) using the MongoDB adapter (@payloadcms/db-mongodb) with any collection that relies on field-level access control to restrict writes under certain conditions. Relational adapters (Postgres, SQLite) are not affected.