logo

Database

Authentication mechanism absence or evasion In payload

Description

Payload CMS default account-unlock access allows authenticated users to reset other accounts' lockouts An Improper Authorization vulnerability exists in PayloadCMS version 3.84.1 due to insufficient access control on the account unlock operation.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions