Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-2q76-m6w6-qgc6 | Payload: Improper access control for MCP API keys |
Tue, 06 Oct 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Payload is a free and open source headless content management system. In @payloadcms/plugin-mcp versions from 3.61.0 until 3.88.0, an authenticated user can manage MCP API keys outside the intended account, enabling privilege escalation through account takeover. This issue is fixed in version 3.88.0. | |
| Title | Payload: Improper access control for MCP API keys | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-06T17:39:44.197Z
Reserved: 2026-10-05T20:37:19.365Z
Link: CVE-2026-105806
No data.
Status : Awaiting Analysis
Published: 2026-10-06T16:17:06.257
Modified: 2026-10-06T20:03:40.690
Link: CVE-2026-105806
No data.
OpenCVE Enrichment
Updated: 2026-10-06T18:45:05Z
-
CWE-862
Missing Authorization
Github GHSA