Junglewise Threat Intelligence

CVE-2026-11779: PayloadCMS Improper Authorization in account unlock operation

CVE-2026-11779 · Severity: medium · CVSS 4 · Published 2026-06-26

Technologies: payload (npm), Payload CMS. Vendors: npm, Payload.

Executive brief

Payload CMS is a popular open-source Next.js-based backend and content management system. An access control flaw allows any authenticated user to unlock other users' locked accounts, potentially granting attackers access to compromised or restricted accounts. This could enable unauthorized access to sensitive data or system functionality if account lockouts were being used to temporarily restrict access.

Technical details

The vulnerability is classified as an improper authorization (CWE-307) flaw affecting the account unlock operation. The root cause is insufficient access control checks on the unlock endpoint, allowing any authenticated user to reset lockout status for arbitrary accounts without verifying authorization. The attack requires network access and valid authentication credentials, but does not require user interaction or administrative privileges. An attacker with a low-privilege user account can call the unlock API to reset lockouts on other user accounts, potentially circumventing account security measures. Payload CMS versions up to 3.88.0 are affected; no patched version has been released as of the advisory publication date.

Affected products

  • Payload Payload CMS <= 3.88.0

Timeline

  • 2026-06-26: disclosed: Published by GitHub Advisory Database and NVD
  • 2026-09-04: advisory: GitHub reviewed and updated advisory

References

Related threats