GHSA-2q76-m6w6-qgc6High

Payload: Improper access control for MCP API keys

Published
October 6, 2026
Last Modified
October 6, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact

Under certain conditions, an authenticated user could manage MCP API keys outside their intended account allowing an attacker to escalate privileges through account takeover.

Applications that do not use @payloadcms/plugin-mcp are not affected.

Patches

Users should upgrade to @payloadcms/plugin-mcp version 3.88.0 or later.

Workarounds

Upgrading is recommended. Until then, disable the MCP plugin or restrict MCP API-key management to trusted users.

🎯 Affected products1

  • npm/@payloadcms/plugin-mcp:>= 3.61.0, < 3.88.0

🔗 References (4)