Unrated severityNVD Advisory· Published Jun 26, 2026· Updated Jun 26, 2026
PayloadCMS 3.84.1 - Authenticated account lockout bypass through default unlock access
CVE-2026-11779
Description
An Improper Authorization vulnerability exists in PayloadCMS version 3.84.1 due to insufficient access control on the account unlock operation.
Patches
Vulnerability mechanics
References
1- fluidattacks.com/es/advisories/stitchesmitrethird-party-advisory
News mentions
0No linked articles in our index yet.