Payload CMS default account-unlock access allows authenticated users to reset other accounts' lockouts
Moderate severity
GitHub Reviewed
Published
Jun 26, 2026
to the GitHub Advisory Database
•
Updated Sep 4, 2026
Description
Published by the National Vulnerability Database
Jun 26, 2026
Published to the GitHub Advisory Database
Jun 26, 2026
Reviewed
Sep 4, 2026
Last updated
Sep 4, 2026
An Improper Authorization vulnerability exists in PayloadCMS version 3.84.1 due to insufficient access control on the account unlock operation.
References