Skip to content

payload

v3.86.0 Feature

This release adds 3 notable features for engineering teams evaluating rollout.

Published 16d Productivity & Wikis
βœ“ No known CVEs patched
Read the diff β†’ Tool health β†’ What is this tool? β†’

✓ No known CVEs patched in this version

Topics

cms content-management content-management-system express graphql headless
+11 more
headless-cms jamstack javascript mongodb nextjs nodejs payload payloadcms postgresql react typescript

Summary

AI summary

Broad release touches 🀝 Contributors, πŸ› Bug Fixes, πŸš€ Features, and βš™οΈ CI.

Changes in this release

Feature Low

Adds collection-level disableBulkDelete option.

Adds collection-level disableBulkDelete option.

Source: llm_adapter@2026-07-15

Confidence: high

β€”
Feature Low

Adds livePreview.openByDefault UI configuration option.

Adds livePreview.openByDefault UI configuration option.

Source: llm_adapter@2026-07-15

Confidence: high

β€”
Feature Low

Backports plugin-form-builder v3 to support translations.

Backports plugin-form-builder v3 to support translations.

Source: granite4.1:30b@2026-07-15-audit

Confidence: low

β€”
Dependency Low

Upgrades pnpm to version 11 in CI.

Upgrades pnpm to version 11 in CI.

Source: llm_adapter@2026-07-15

Confidence: high

β€”
Bugfix Medium

Coerces schedulePublish doc.value to collection ID type before update.

Coerces schedulePublish doc.value to collection ID type before update.

Source: llm_adapter@2026-07-15

Confidence: high

β€”
Bugfix Medium

Escapes regex metacharacters in isURLAllowed pathname allow‑list.

Escapes regex metacharacters in isURLAllowed pathname allow‑list.

Source: llm_adapter@2026-07-15

Confidence: high

β€”
Bugfix Medium

Respects disabled GraphQL config in v3 backport.

Respects disabled GraphQL config in v3 backport.

Source: llm_adapter@2026-07-15

Confidence: high

β€”
Bugfix Medium

Allows access to files reuploaded on a draft entry.

Allows access to files reuploaded on a draft entry.

Source: llm_adapter@2026-07-15

Confidence: high

β€”
Bugfix Medium

Runs tenant delete cleanup inside the request transaction for plugin-multi-tenant.

Runs tenant delete cleanup inside the request transaction for plugin-multi-tenant.

Source: llm_adapter@2026-07-15

Confidence: high

β€”
Bugfix Low

Uses qs-esm allowEmptyArrays parameter in SDK.

Uses qs-esm allowEmptyArrays parameter in SDK.

Source: granite4.1:30b@2026-07-15-audit

Confidence: low

β€”
Bugfix Low

Skips presentational fields in form state when admin.condition is false.

Skips presentational fields in form state when admin.condition is false.

Source: granite4.1:30b@2026-07-15-audit

Confidence: low

β€”
Bugfix Low

Prevents slug field error tooltip from hiding lock button.

Prevents slug field error tooltip from hiding lock button.

Source: granite4.1:30b@2026-07-15-audit

Confidence: low

β€”
Full changelog

v3.86.0 (2026-07-10)

πŸš€ Features

  • collection-level disableBulkDelete (#17207) (ca02cdc)
  • plugin-form-builder: v3 backport to support translations (#17255) (2cde8c8)
  • ui: add livePreview.openByDefault config option (#17213) (f23b693)

πŸ› Bug Fixes

  • coerce schedulePublish doc.value to collection ID type before update (#17238) (7de11b2)
  • escape regex metacharacters in isURLAllowed pathname allow-list (#17237) (2061859)
  • respect disabled GraphQL config, v3 backport (#17228) (9e9c35a)
  • allow access to files reuploaded on a draft (#17209) (f02d22a)
  • plugin-multi-tenant: run tenant delete cleanup inside the request transaction (#17175) (d128fde)
  • sdk: use qs-esm allowEmptyArrays parameter (#17208) (c7dc68e)
  • ui: presentational fields skipped in form state when admin.condition is false (#17224) (f31f26d)
  • ui: prevent slug field error tooltip from hiding lock button (#15885) (908fba1)

βš™οΈ CI

🀝 Contributors

  • Jessica Rynkar (@JessRynkar)
  • Γ†var Þór Gunnlaugsson (@aevarOrigo)
  • Sasha (@r1tsuu)
  • Herman Ciechanowiec (@ciechanowiec)
  • Vivek Tyagi (@darkspirit2802)
  • Noah Bachmann (@noahbachmann)
  • Jake Fletcher (@jacobsfletch)
  • Amelia (@LimChorngUan)
  • German Jablonski (@GermanJablo)
  • Elliot DeNolf (@denolfe)
  • Jarrod Flesch (@JarrodMFlesch)

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track payload

Get notified when new releases ship.

Sign up free

About payload

Payload is the open-source, fullstack Next.js framework, giving you instant backend superpowers. Get a full TypeScript backend and admin panel instantly. Use Payload as a headless CMS or for building powerful applications.

All releases β†’

Related context

Beta — feedback welcome: [email protected]