An Improper Authorization vulnerability exists in PayloadCMS version 3.84.1 due to insufficient access control on the account unlock operation.
Metrics
Affected Vendors & Products
References
History
Fri, 26 Jun 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An Improper Authorization vulnerability exists in PayloadCMS version 3.84.1 due to insufficient access control on the account unlock operation. | |
| Title | PayloadCMS 3.84.1 - Authenticated account lockout bypass through default unlock access | |
| First Time appeared |
Payloadcms
Payloadcms payloadcms |
|
| Weaknesses | CWE-307 | |
| CPEs | cpe:2.3:a:payloadcms:payloadcms:3.84.1:*:linux:*:*:*:*:* cpe:2.3:a:payloadcms:payloadcms:3.84.1:*:macos:*:*:*:*:* cpe:2.3:a:payloadcms:payloadcms:3.84.1:*:windows:*:*:*:*:* |
|
| Vendors & Products |
Payloadcms
Payloadcms payloadcms |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Fluid Attacks
Published:
Updated: 2026-06-26T17:15:31.958Z
Reserved: 2026-06-09T12:26:37.643Z
Link: CVE-2026-11779
No data.
No data.
No data.
OpenCVE Enrichment
No data.