GHSA-jg8r-5jh2-v2xjMedium

Payload CMS default account-unlock access allows authenticated users to reset other accounts' lockouts

Published
June 26, 2026
Last Modified
September 4, 2026

🔗 CVE IDs covered (1)

📋 Description

An Improper Authorization vulnerability exists in PayloadCMS version 3.84.1 due to insufficient access control on the account unlock operation.

🎯 Affected products1

  • npm/payload:<= 3.88.0

🔗 References (4)