{"id":"GHSA-jq29-r496-r955","summary":"payload-preferences has Cross-Collection IDOR in Access Control (Multi-Auth Environments)","details":"### Impact\n\nA cross-collection Insecure Direct Object Reference (IDOR) vulnerability exists in the `payload-preferences` internal collection. In multi-auth collection environments using Postgres or SQLite with default serial/auto-increment IDs, authenticated users from one auth collection can read and delete preferences belonging to users in different auth collections when their numeric IDs collide.\n\n**Users are affected if ALL of these are true:**\n\n- Multiple auth collections configured (e.g., `admins` + `customers`)\n- Postgres or SQLite database adapter with serial/auto-increment IDs\n- Users in different auth collections with the same numeric ID\n\n**Not affected:**\n\n- `@payloadcms/db-mongodb` adapter\n- Single auth collection environments\n- Postgres/SQLite with `idType: 'uuid'`\n\n### Patches\n\nThis vulnerability has been patched in **v3.74.0**. Users should upgrade to v3.74.0 or later.\n\n### Workarounds\n\nThere is no workaround other than upgrading. Users with multiple auth collections using Postgres or SQLite with serial IDs should upgrade immediately.","aliases":["CVE-2026-25574"],"modified":"2026-02-07T00:52:43.263608Z","published":"2026-02-05T21:02:20Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-02-05T21:02:20Z","nvd_published_at":"2026-02-06T22:16:11Z","cwe_ids":["CWE-639"],"severity":"MODERATE"},"references":[{"type":"WEB","url":"https://github.com/payloadcms/payload/security/advisories/GHSA-jq29-r496-r955"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-25574"},{"type":"PACKAGE","url":"https://github.com/payloadcms/payload"}],"affected":[{"package":{"name":"payload","ecosystem":"npm","purl":"pkg:npm/payload"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"3.74.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-jq29-r496-r955/GHSA-jq29-r496-r955.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"}]}