What happened
An authenticated user can manage MCP API keys outside the intended account in @payloadcms/plugin-mcp (< 3.88.0), enabling privilege escalation through account takeover via those keys (CWE-862). Fixed in 3.88.0.
Why it matters
Payload's official MCP plugin exposes CMS data to AI agents via those API keys; being able to mint/rotate another user's MCP keys lets an attacker impersonate that account through the agent tool surface, reading or modifying CMS content with the victim's permissions.
Attack vector
Authenticated (low-priv) API calls that manage MCP API key records belonging to another account without an ownership check.
Affected systems
@payloadcms/plugin-mcp 3.61.0–3.88.0 (Payload 3.x)
Mitigation
Upgrade to Payload 3.88.0 / @payloadcms/plugin-mcp 3.88.0; audit rotation of existing MCP keys.