CVE-2026-106100 | payloadcms Payload up to 3.86.x @payloadcms/db-mongodb access control
A vulnerability classified as problematic was found in payloadcms Payload up to 3.86.x. Affected is an unknown function of the component @payloadcms/db-mongodb. Executing a manipulation can lead to improper access controls.
This vulnerability appears as CVE-2026-106100. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is advised.VulDB Recent EntriesRead More