CVE-2026-105806: Payload: Improper access control for MCP API keys
Impact Under certain conditions, an authenticated user could manage MCP API keys outside their intended account allowing an attacker to escalate privileges through account takeover.
Applications that do not use @payloadcms/plugin-mcp are not affected.
Patches Users should upgrade to @payloadcms/plugin-mcp version 3.88.0 or later.
Workarounds Upgrading is recommended. Until then, disable the MCP plugin or restrict MCP API-key management to trusted users.
Other sources
Payload is a free and open source headless content management system. In @payloadcms/plugin-mcp versions from 3.61.0 until 3.88.0, an authenticated user can manage MCP API keys outside the intended account, enabling privilege escalation through account takeover. This issue is fixed in version 3.88.0.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/@payloadcms/plugin-mcpto a version that resolves this vulnerability.Fixed in 3.88.0 - Upgrade
Upgrade
@payloadcms/plugin-mcpto a version that resolves this vulnerability.Fixed in 3.88.0 - Configuration
Disable the MCP plugin until upgrading to version 3.88.0 or later.
@payloadcms/plugin-mcp enabled = false - Compensating control
Restrict MCP API-key management to trusted users until upgrading to version 3.88.0 or later.
Event History
Frequently Asked Questions
Which deployments are affected?
Only applications using @payloadcms/plugin-mcp are affected. The vulnerable version range is 3.61.0 up to, but not including, 3.88.0.
What does an attacker need to exploit this issue?
An attacker needs to be an authenticated user. Under certain conditions, they can manage MCP API keys outside their intended account and use this to escalate privileges through account takeover.
Are applications that do not use the MCP plugin affected?
No. Applications that do not use @payloadcms/plugin-mcp are not affected.
What should be done if an immediate upgrade is not possible?
Disable the MCP plugin or restrict MCP API-key management to trusted users until an upgrade can be completed. The recommended remediation is upgrading to version 3.88.0 or later.