Data Exposure in Payload Headless CMS Product
CVE-2026-105849

7.7HIGH

Key Information:

Vendor

Payloadcms

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-105849?

In Payload CMS, versions ranging from 3.0.0 prior to 3.90.0 and certain Canary versions before 4.0.0-canary.34, there exists a vulnerability where users with basic read access can gain unauthorized access to active API keys. This exposure allows them to leverage the permissions associated with the affected accounts until those keys are either rotated or disabled. This issue can lead to serious security risks including unauthorized data access and manipulation. Updated versions 3.90.0 and 4.0.0-canary.34 contain necessary patches to mitigate this risk.

Affected Version(s)

payload >= 3.0.0, < 3.90.0 < 3.0.0, 3.90.0

payload >= 4.0.0-canary.0, < 4.0.0-canary.34 < 4.0.0-canary.0, 4.0.0-canary.34

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.