MajorCritical vulnerability
CVE-2026-105806: Payload: Improper access control for MCP API keys
GitHub Advisories · officialPublished Oct 6, 2026Risk 37/100
### Impact Under certain conditions, an authenticated user could manage MCP API keys outside their intended account allowing an attacker to escalate privileges through account takeover. Applications that do not use `@payloadcms/plugin-mcp` are not affected. ### Patches Users should upgrade to `@payloadcms/plugin-mcp` version `3.88.0` or later. ### Workarounds Upgrading is recommended. Until then, disable the MCP plugin or restrict MCP API-key management to trusted users.
Recommended action
Recommended action
Upgrade affected packages to a patched version: @payloadcms/plugin-mcp 3.88.0.
Technical details
- Vendor
- Not specified
- Product
- @payloadcms/plugin-mcp
- Exploitation
- none known
- Evidence
- official
Evidence and sources
This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source