CVE-2026-105806: Privilege Escalation and Missing Authorization in @payloadcms/plugin-mcp
Vulnerability ID: CVE-2026-105806
CVSS Score: 8.6
Published: 2026-10-06
CVE-2026-105806 is an improper access control vulnerability within the Model Context Protocol (MCP) plugin for Payload CMS. Authenticated users with low privileges can manipulate API key creation and mapping to associate keys with arbitrary users, including administrators. This allows total session takeovers and privilege escalation via MCP-authenticated API requests.
TL;DR
A missing authorization check in @payloadcms/plugin-mcp allows authenticated low-privilege users to generate MCP API keys mapped to administrative accounts, resulting in privilege escalation and full account takeover.
Technical Details
- CWE ID: CWE-862
- Attack Vector: Network
- CVSS v4.0: 8.6
- Exploit Status: Unproven / None
- KEV Status: Not Listed
Affected Systems
- Payload CMS
- @payloadcms/plugin-mcp
-
@payloadcms/plugin-mcp: >= 3.61.0, < 3.88.0 (Fixed in:
3.88.0)
Code Analysis
Commit: 025581d
Fix access control permissions on MCP API key collections and relationship fields
Mitigation Strategies
- Upgrade @payloadcms/plugin-mcp to version 3.88.0 or higher.
- Disable the MCP plugin if it is not actively required.
- Manually override collection permissions using overrideApiKeyCollection hook.
Remediation Steps:
- Verify the current version of @payloadcms/plugin-mcp in package.json.
- Run npm install @payloadcms/plugin-mcp@3.88.0 or yarn upgrade.
- Deploy the updated code and restart the Payload CMS service.
References
- GitHub Security Advisory GHSA-2q76-m6w6-qgc6
- Official Patch Commit
- Release v3.88.0
- CVE-2026-105806 Record
Read the full report for CVE-2026-105806 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)