An Improper Authorization vulnerability exists in PayloadCMS version 3.84.1 due to insufficient access control on the account unlock operation.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 26 Jun 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An Improper Authorization vulnerability exists in PayloadCMS version 3.84.1 due to insufficient access control on the account unlock operation. | |
| Title | PayloadCMS 3.84.1 - Authenticated account lockout bypass through default unlock access | |
| First Time appeared |
Payloadcms
Payloadcms payloadcms |
|
| Weaknesses | CWE-307 | |
| CPEs | cpe:2.3:a:payloadcms:payloadcms:3.84.1:*:linux:*:*:*:*:* cpe:2.3:a:payloadcms:payloadcms:3.84.1:*:macos:*:*:*:*:* cpe:2.3:a:payloadcms:payloadcms:3.84.1:*:windows:*:*:*:*:* |
|
| Vendors & Products |
Payloadcms
Payloadcms payloadcms |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Fluid Attacks
Published:
Updated: 2026-06-26T17:15:31.958Z
Reserved: 2026-06-09T12:26:37.643Z
Link: CVE-2026-11779
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses