Data Exposure in Payload Headless CMS Product
CVE-2026-105849
7.7HIGH
What is CVE-2026-105849?
In Payload CMS, versions ranging from 3.0.0 prior to 3.90.0 and certain Canary versions before 4.0.0-canary.34, there exists a vulnerability where users with basic read access can gain unauthorized access to active API keys. This exposure allows them to leverage the permissions associated with the affected accounts until those keys are either rotated or disabled. This issue can lead to serious security risks including unauthorized data access and manipulation. Updated versions 3.90.0 and 4.0.0-canary.34 contain necessary patches to mitigate this risk.
Affected Version(s)
payload >= 3.0.0, < 3.90.0 < 3.0.0, 3.90.0
payload >= 4.0.0-canary.0, < 4.0.0-canary.34 < 4.0.0-canary.0, 4.0.0-canary.34
