Payload relationship-query authorization bypass
Moderate severity
GitHub Reviewed
Published
Sep 18, 2026
in
payloadcms/payload
•
Updated Oct 6, 2026
Package
Affected versions
< 3.90.0
>= 4.0.0-canary.0, < 4.0.0-canary.34
Patched versions
3.90.0
4.0.0-canary.34
Description
Published to the GitHub Advisory Database
Oct 6, 2026
Reviewed
Oct 6, 2026
Last updated
Oct 6, 2026
Impact
A readable collection could expose information about protected documents in a related collection.
You are affected if:
Patches
Users should upgrade Payload packages to
>= 3.90.0or>= 4.0.0-canary.34.Workarounds
There is no complete workaround. Upgrade Payload packages
>= 3.90.0or>= 4.0.0-canary.34.References