CVE-2026-105849: Sensitive Data Exposure and Privilege Escalation in Payload CMS API Key Authentication
Vulnerability ID: CVE-2026-105849
CVSS Score: 7.7
Published: 2026-10-06
A sensitive data exposure vulnerability in Payload CMS allows authenticated low-privilege users to retrieve decrypted, plaintext API keys of other users, including administrators, leading to full administrative account takeover and privilege escalation.
TL;DR
Vulnerable versions of Payload CMS fail to restrict read access to the dynamically generated apiKey field, exposing active plaintext API keys to any user with standard read access to user collections.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-201, CWE-862
- Attack Vector: Network
- CVSS Score: 7.7
- EPSS Score: N/A
- Impact: Account Takeover / Privilege Escalation
- Exploit Status: poc
- KEV Status: Not Listed
Affected Systems
- Payload CMS running versions 3.x prior to 3.90.0
- Payload CMS running versions 4.x canary prior to 4.0.0-canary.34
-
payload: >= 3.0.0 < 3.90.0 (Fixed in:
3.90.0) -
payload: >= 4.0.0-canary.0 < 4.0.0-canary.34 (Fixed in:
4.0.0-canary.34)
Code Analysis
Commit: 880d2e9
feat: secure default useAPIKey behavior and add reveal endpoint
...
Exploit Details
- GitHub Security Advisory: Technical writeup detailing read access to API keys
Mitigation Strategies
- Upgrade Payload CMS to a patched version
- Explicitly configure the apiKey field with a hardcoded read-access block of () => false
- Restrict user collection read permissions so users can only access their own documents
- Rotate potentially compromised API keys
Remediation Steps:
- For v3 applications, update dependency 'payload' to version 3.90.0 or higher.
- For v4 applications, update dependency 'payload' to version 4.0.0-canary.34 or higher.
- Run a global search on the project codebase for 'useAPIKey: true' configurations.
- For any collections running API key authentication, enforce restricted read policies on the collection-level access configuration.
- To securely enable administrators to view keys via the Admin UI, explicitly specify auth.useAPIKey.reveal = true in the collection configuration post-upgrade.
References
- GitHub Security Advisory GHSA-238x-w2j9-gwwr
- Payload CMS Fix Commit
- Payload CMS Release v3.90.0
- CVE-2026-105849 Record
Read the full report for CVE-2026-105849 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)