Medium severityOSV Advisory· Published Jun 26, 2026· Updated Jun 26, 2026
CVE-2026-11779
CVE-2026-11779
Description
An Improper Authorization vulnerability exists in PayloadCMS version 3.84.1 due to insufficient access control on the account unlock operation.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
payloadnpm | <= 3.88.0 | — |
Affected products
2<3.84.1+ 1 more
- (no CPE)range: <3.84.1
- (no CPE)range: 3.84.1, v3.84.1
Patches
Vulnerability mechanics
References
3- github.com/advisories/GHSA-jg8r-5jh2-v2xjghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-11779ghsaADVISORY
- fluidattacks.com/es/advisories/stitchesnvdWEB
News mentions
0No linked articles in our index yet.