MEDIUM 5.3 NVD
CVE-2026-93363
The @payloadcms/storage-vercel-blob storage adapter for Payload contains an improper access control vulnerability that allows authenticated users to bypass coll
The @payloadcms/storage-vercel-blob storage adapter for Payload contains an improper access control vulnerability that allows authenticated users to bypass collection-level permissions by accessing the client-upload route directly. Attackers can upload files through the client-upload endpoint without possessing the required collection access permissions, circumventing the intended access control enforcement.
References
- https://github.com/payloadcms/payload/security/advisories/GHSA-mc8m-rr6c-r5qr
- https://www.vulncheck.com/advisories/payload-cms-storage-vercel-blob-adapter-improper-acce
This medium severity vulnerability with a CVSS score of 5.3 was published on 2026-09-25 via NVD.
vulnfeed aggregates 11568 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.