Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
7.7
CVE-2026-105849: Payload CMS lets read‑only users see active API keys
CVE-2026-105849 · published 3 days ago
Summary
Versions of Payload CMS from 3.0.0 up to 3.90.0 (and certain canary builds) allow users who only have read permission to view authentication documents that contain active API keys. With those keys they can act as the account owner until the keys are changed or disabled. Upgrade to version 3.90.0 or later (or the specified canary release) to stop this from happening.
What to do
- Update elliotpayload payload to version 3.90.0.
- Update elliotpayload payload to version 4.0.0-canary.34.
- Update payload to version 3.90.0.
- Update payload to version 4.0.0-canary.34.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | payloadcms | payload | >= 3.0.0, < 3.90.0 |
| npm | elliotpayload | payload |
>= 3.0.0, < 3.90.0 >= 4.0.0-canary.0, < 4.0.0-canary.34 Fix: upgrade to 3.90.0
|
| npm | – | payload |
>= 3.0.0, < 3.90.0 >= 4.0.0-canary.0, < 4.0.0-canary.34 Fix: upgrade to 3.90.0
|
Original advisory text
Payload vulnerable to API key disclosure through ordinary document reads
Payload is a free and open source headless content management system. In versions from 3.0.0 before 3.90.0 and canary versions before 4.0.0-canary.34, users with ordinary read access to other authentication documents in a collection with useAPIKey enabled can obtain active API keys and exercise the target accounts' permissions until those keys are rotated or disabled. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
References
- https://github.com/payloadcms/payload Product
- https://github.com/payloadcms/payload/security/advisories/GHSA-238x-w2j9-gwwr
- https://github.com/payloadcms/payload/commit/880d2e900be22cd66a9e939f2b3e702fa41...
- https://github.com/payloadcms/payload/releases/tag/v3.90.0
- https://github.com/advisories/GHSA-238x-w2j9-gwwr
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/105xxx/CVE-2026-1058... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-105849 Vendor Advisory
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Severity
7.7
High
Type
CWE-201Insertion of Sensitive Information Into Sent Data
CWE-862Missing Authorization
Timeline
Published6 Oct 2026
Updated9 Oct 2026
First seen6 Oct 2026
Sources
CVE-2026-105849 · NVD
CVE-2026-105849 · MITRE
GHSA-238x-w2j9-gwwr · GHSA
CVE-2026-105849 · OSV
GHSA-238x-w2j9-gwwr · OSV
Track software like this
Free during beta