VYPR
Medium severityOSV Advisory· Published Jun 26, 2026· Updated Jun 26, 2026

CVE-2026-11779

CVE-2026-11779

Description

An Improper Authorization vulnerability exists in PayloadCMS version 3.84.1 due to insufficient access control on the account unlock operation.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
payloadnpm
<= 3.88.0

Affected products

2
  • Payloadcms/Payloadllm-fuzzy2 versions
    <3.84.1+ 1 more
    • (no CPE)range: <3.84.1
    • (no CPE)range: 3.84.1, v3.84.1

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.