CVE-2026-105849
Received Received - Intake

Authentication Key Exposure in Payload CMS

Vulnerability report for CVE-2026-105849, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: GitHub, Inc.

Description

Payload is a free and open source headless content management system. In versions from 3.0.0 before 3.90.0 and canary versions before 4.0.0-canary.34, users with ordinary read access to other authentication documents in a collection with useAPIKey enabled can obtain active API keys and exercise the target accounts' permissions until those keys are rotated or disabled. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
payloadcms payload >= 3.0.0, < 3.90.0
payloadcms payload >= 4.0.0-canary.0, < 4.0.0-canary.34

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
CWE-201 The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Payload CMS versions from 3.0.0 before 3.90.0 and canary versions before 4.0.0-canary.34. Users with read access to other authentication documents in a collection with useAPIKey enabled can obtain active API keys and use the target accounts' permissions until the keys are rotated or disabled.

Detection Guidance

To detect this vulnerability, check Payload CMS versions between 3.0.0 and 3.90.0 or canary versions before 4.0.0-canary.34. Verify if useAPIKey is enabled in collections with read access. Inspect API key rotation logs for unauthorized access patterns.

Impact Analysis

An attacker with read access could escalate privileges by obtaining active API keys, allowing them to perform actions on behalf of other users. This could lead to unauthorized data access, modification, or deletion within the CMS.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating confidentiality requirements in GDPR and HIPAA. Organizations using affected versions may face compliance violations, data breaches, and potential legal penalties.

Mitigation Strategies

Update Payload CMS to version 3.90.0 or later for stable releases, or 4.0.0-canary.34 or later for canary versions. Disable the useAPIKey feature if not required or restrict read access to authentication documents.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105849. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart