Vulnerability  ·  2026-10-07

Payload CMS @payloadcms/plugin-mcp missing authorization — MCP API key management outside intended account (account takeover)

VulnerabilityMedium impactGlobalCVE-2026-105806
An authenticated user can manage MCP API keys outside the intended account in @payloadcms/plugin-mcp (< 3.88.0), enabling privilege escalation through account takeover via those keys (CWE-862). Fixed in 3.88.0.
Payload's official MCP plugin exposes CMS data to AI agents via those API keys; being able to mint/rotate another user's MCP keys lets an attacker impersonate that account through the agent tool surface, reading or modifying CMS content with the victim's permissions.
Authenticated (low-priv) API calls that manage MCP API key records belonging to another account without an ownership check.
@payloadcms/plugin-mcp 3.61.0–3.88.0 (Payload 3.x)
Upgrade to Payload 3.88.0 / @payloadcms/plugin-mcp 3.88.0; audit rotation of existing MCP keys.
NVD CVE-2026-105806GitHub advisory GHSA-2q76-m6w6-qgc6Fix commit
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →