Description
A cross-collection Insecure Direct Object Reference (IDOR) vulnerability exists in the payload-preferences internal collection.
Recommendation
Update the payload package to the latest compatible version. Followings are version details:
- Affected version(s): < 3.74.0
- Patched version(s): 3.74.0
References
Could your website be exposed too?
SmartScanner can check your website for payload-preferences has Cross-Collection IDOR in Access Control (Multi-Auth Environments) and gives you actionable findings to investigate.
Start a free scanRelated Issues
- OneUptime has broken access control in GitHub App installation flow that allows unauthorized project binding - CVE-2026-30920
- LangGraph has NoSQL parameter injection in MongoDBSaver, allowing cross-tenant state access - CVE-2026-48121
- Lobe Chat has IDOR in Knowledge Base File Removal that Allows Cross User File Deletion - CVE-2026-23522
- OneUptime has authorization bypass via client‑controlled is-multi-tenant-query header that leads to cross‑tenant data ex - CVE-2026-30956
You might also like:
See something that needs correcting? Let us knowUpdated February 07, 2026


