PT-2026-52847 · Unknown · Payloadcms

·

CVE-2026-11779

·

Published

2026-06-26

·

Updated

2026-06-26

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions PayloadCMS version 3.84.1
Description An improper authorization issue exists due to insufficient access control on the account unlock operation, which allows an authenticated user to bypass account lockout.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Restriction of Excessive Authentication Attempts

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-11779
GHSA-JG8R-5JH2-V2XJ

Affected Products

Payloadcms