DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-105849: CVE-2026-105849: Sensitive Data Exposure and Privilege Escalation in Payload CMS API Key Authentication

CVE-2026-105849: Sensitive Data Exposure and Privilege Escalation in Payload CMS API Key Authentication

Vulnerability ID: CVE-2026-105849
CVSS Score: 7.7
Published: 2026-10-06

A sensitive data exposure vulnerability in Payload CMS allows authenticated low-privilege users to retrieve decrypted, plaintext API keys of other users, including administrators, leading to full administrative account takeover and privilege escalation.

TL;DR

Vulnerable versions of Payload CMS fail to restrict read access to the dynamically generated apiKey field, exposing active plaintext API keys to any user with standard read access to user collections.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-201, CWE-862
  • Attack Vector: Network
  • CVSS Score: 7.7
  • EPSS Score: N/A
  • Impact: Account Takeover / Privilege Escalation
  • Exploit Status: poc
  • KEV Status: Not Listed

Affected Systems

  • Payload CMS running versions 3.x prior to 3.90.0
  • Payload CMS running versions 4.x canary prior to 4.0.0-canary.34
  • payload: >= 3.0.0 < 3.90.0 (Fixed in: 3.90.0)
  • payload: >= 4.0.0-canary.0 < 4.0.0-canary.34 (Fixed in: 4.0.0-canary.34)

Code Analysis

Commit: 880d2e9

feat: secure default useAPIKey behavior and add reveal endpoint

...
Enter fullscreen mode Exit fullscreen mode

Exploit Details

Mitigation Strategies

  • Upgrade Payload CMS to a patched version
  • Explicitly configure the apiKey field with a hardcoded read-access block of () => false
  • Restrict user collection read permissions so users can only access their own documents
  • Rotate potentially compromised API keys

Remediation Steps:

  1. For v3 applications, update dependency 'payload' to version 3.90.0 or higher.
  2. For v4 applications, update dependency 'payload' to version 4.0.0-canary.34 or higher.
  3. Run a global search on the project codebase for 'useAPIKey: true' configurations.
  4. For any collections running API key authentication, enforce restricted read policies on the collection-level access configuration.
  5. To securely enable administrators to view keys via the Admin UI, explicitly specify auth.useAPIKey.reveal = true in the collection configuration post-upgrade.

References


Read the full report for CVE-2026-105849 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)