Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
7.7

CVE-2026-105849: Payload CMS lets read‑only users see active API keys

CVE-2026-105849 · published 3 days ago
Summary

Versions of Payload CMS from 3.0.0 up to 3.90.0 (and certain canary builds) allow users who only have read permission to view authentication documents that contain active API keys. With those keys they can act as the account owner until the keys are changed or disabled. Upgrade to version 3.90.0 or later (or the specified canary release) to stop this from happening.

What to do
  • Update elliotpayload payload to version 3.90.0.
  • Update elliotpayload payload to version 4.0.0-canary.34.
  • Update payload to version 3.90.0.
  • Update payload to version 4.0.0-canary.34.
Affected software
Ecosystem VendorProductAffected versions
– payloadcms payload >= 3.0.0, < 3.90.0
npm elliotpayload payload >= 3.0.0, < 3.90.0
>= 4.0.0-canary.0, < 4.0.0-canary.34
Fix: upgrade to 3.90.0
npm – payload >= 3.0.0, < 3.90.0
>= 4.0.0-canary.0, < 4.0.0-canary.34
Fix: upgrade to 3.90.0
Original advisory text
Payload vulnerable to API key disclosure through ordinary document reads
Payload is a free and open source headless content management system. In versions from 3.0.0 before 3.90.0 and canary versions before 4.0.0-canary.34, users with ordinary read access to other authentication documents in a collection with useAPIKey enabled can obtain active API keys and exercise the target accounts' permissions until those keys are rotated or disabled. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
7.7 High
Exploitation
<1% chance of attack within 30 days
Type
CWE-201Insertion of Sensitive Information Into Sent Data
CWE-862Missing Authorization
Timeline
Published6 Oct 2026
Updated9 Oct 2026
First seen6 Oct 2026
Track software like this
Free during beta