MEDIUM
CVE-2026-11779
CVSS
5.3
Description
An Improper Authorization vulnerability exists in PayloadCMS version 3.84.1 due to insufficient access control on the account unlock operation.
Summary dbcve.org
PayloadCMS 3.84.1 contains an improper authorization vulnerability in the account unlock mechanism. The application fails to properly validate user permissions before allowing account unlock operations, potentially allowing authenticated users to unlock other user accounts without sufficient privileges.
Mitigation
Implement proper role-based access control (RBAC) checks on the account unlock endpoint to verify the requesting user has appropriate permissions. Restrict the unlock operation to administrative roles only.
Weakness (CWE)
CWE-307
EPSS Score
0.36%
Probability of exploitation in next 30 days
30.3th percentile
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.