Payload: Field access control bypass on auth collections
Critical severity
GitHub Reviewed
Published
Sep 18, 2026
in
payloadcms/payload
•
Updated Oct 6, 2026
Package
Affected versions
> 3.0.0, < 3.90.0
> 4.0.0-canary.0, < 4.0.0-canary.34
Patched versions
3.90.0
4.0.0-canary.34
Description
Published to the GitHub Advisory Database
Oct 6, 2026
Reviewed
Oct 6, 2026
Last updated
Oct 6, 2026
Impact
Payload's duplicate operation copies field values from the source document even when a field is hidden, or its
access.readoraccess.createrule would reject the value for that caller.The
disableDuplicatecollection setting, enabled by default on auth collections, did not stop this.Patches
Users should upgrade Payload packages to
>= 3.90.0or>= 4.0.0-canary.34.Workarounds
Add a beforeDuplicate field hook to fields and set the value to empty or your default value.
References