CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



CVE-2026-105849

CVE-2026-105849: Sensitive Data Exposure and Privilege Escalation in Payload CMS API Key Authentication

Amit Schendel
Amit Schendel
Senior Security Researcher

Oct 6, 2026·5 min read·3 visits

Executive Summary (TL;DR)

Vulnerable versions of Payload CMS fail to restrict read access to the dynamically generated apiKey field, exposing active plaintext API keys to any user with standard read access to user collections.

A sensitive data exposure vulnerability in Payload CMS allows authenticated low-privilege users to retrieve decrypted, plaintext API keys of other users, including administrators, leading to full administrative account takeover and privilege escalation.

Vulnerability Overview

The affected component is Payload's default API key authentication mechanism. When a collection configuration enables useAPIKey, the CMS generates default authentication fields, specifically apiKey. In vulnerable versions, Payload fails to enforce adequate field-level read-authorization controls or default masking on this generated apiKey field.

Consequently, any user with ordinary read access to other authentication documents in that collection can retrieve active, unmasked API keys for other users.

This exposes a substantial attack surface, as low-privilege users can query the /api/users endpoint or custom authentication collections and retrieve active keys of higher-privilege administrative accounts. The bug falls under CWE-201 (Insertion of Sensitive Information Into Sent Data) and CWE-862 (Missing Authorization).

Root Cause Analysis

In Payload CMS, collections configured with authentication support can generate API keys to allow external integrations or API clients to execute operations. Setting useAPIKey to true dynamically inserts default fields into the collection schema, including enableAPIKey and apiKey.

The root cause of the vulnerability lies in the lack of read-level restrictions in the default field definition of apiKey under packages/payload/src/auth/baseFields/apiKey.ts. The default apiKey field definition did not implement explicit field-level access control, such as access.read = () => false. Consequently, the field inherited the read permissions of the parent document.

Furthermore, the field definition integrated an afterRead hook that mapped to decryptKey. Whenever a read operation was executed on a document within the collection, the database engine returned the ciphertext, the hook automatically decrypted it using the primary payload secret, and the plaintext API key was rendered directly in the output JSON.

Code Analysis

An examination of the patch in commit 880d2e900be22cd66a9e939f2b3e702fa413180f reveals the structural remediation of this design flaw. The developer replaced the implicit read inheritance with a hard block on standard read operations. The access.read attribute is now explicitly defined as () => false for the apiKey field.

The patch also eliminates the automated decryption process during standard reads. The decryptKey hook was completely removed, replaced by the omitEncryptedAPIKey hook within afterRead, which guarantees that the raw or encrypted key cannot be leaked even if database extraction occurs. A new dedicated and secured reveal endpoint (/:id/api-key/reveal) was introduced, implementing granular verification checks that demand admin panel access capabilities alongside read and write permissions on the targeted document.

Exploitation Scenario

Exploitation requires that the attacker has authenticated credentials with standard read permissions to the user collection. In a standard multi-tenant or multi-user configuration, standard users or content authors might have permissions to view other profiles, or a lax API configuration might permit broad read access to the /api/users endpoint.

The attacker queries the endpoint using standard HTTP REST or GraphQL operations. Because the apiKey field is decrypted on read, the server returns the plaintext API keys in the response payload.

The attacker extracts the active API key of an administrative user and places it in the Authorization header of subsequent requests. Since the API key authentication middleware identifies the key and maps it to the target user context, the attacker assumes the full permissions of the administrative account, achieving complete privilege escalation.

Impact Assessment

An attacker who exploits this vulnerability gains full, unauthenticated administrative access over the affected CMS instance. Because API keys bypass multi-factor authentication and standard login logging protocols, the attacker's activities may remain undetected within standard authentication monitoring channels.

The vulnerability carries a CVSS v4.0 base score of 7.7, reflecting high confidentiality, integrity, and availability impacts within the local CMS instance. While the vulnerability is restricted to the Payload CMS application layer, administrative compromise allows complete data exfiltration, database tampering, and arbitrary execution of any integrated headless processes.

Remediation

The primary remediation strategy is upgrading the Payload installation to version 3.90.0 or higher, or 4.0.0-canary.34 or higher. These releases implement the hardened field configuration and secure disclosure endpoints.

If upgrading is not immediately possible, security teams should implement immediate manual overrides. This includes modifying collection definitions to explicitly set the access.read constraint of the apiKey field to () => false.

Additionally, read permissions on user collections must be locked down using granular access rules so that non-administrative users can only read their own documents. Finally, any potentially exposed API keys must be immediately rotated to invalidate cached sessions.

Official Patches

Payload CMSFix commit implementing secure API key fields

Fix Analysis (1)

Technical Appendix

CVSS Score
7.7/ 10
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Systems

Payload CMS running versions 3.x prior to 3.90.0Payload CMS running versions 4.x canary prior to 4.0.0-canary.34

Affected Versions Detail

Product
Affected Versions
Fixed Version
payload
Payload CMS
>= 3.0.0 < 3.90.03.90.0
payload
Payload CMS
>= 4.0.0-canary.0 < 4.0.0-canary.344.0.0-canary.34
AttributeDetail
CWE IDCWE-201, CWE-862
Attack VectorNetwork
CVSS Score7.7
EPSS ScoreN/A
ImpactAccount Takeover / Privilege Escalation
Exploit Statuspoc
KEV StatusNot Listed

MITRE ATT&CK Mapping

T1068Exploitation for Privilege Escalation
Privilege Escalation
T1552.001Unsecured Credentials: Credentials In Files
Credential Access
CWE-201
Insertion of Sensitive Information Into Sent Data

The product houses sensitive information in a resource that is accessible to unauthorized actors, resulting in the exposure of this information.

Known Exploits & Detection

GitHub Security AdvisoryTechnical writeup detailing read access to API keys

Vulnerability Timeline

Fix commit authored
2026-09-16
GitHub Security Advisory Published
2026-10-06

References & Sources

  • [1]GitHub Security Advisory GHSA-238x-w2j9-gwwr
  • [2]Payload CMS Fix Commit
  • [3]Payload CMS Release v3.90.0
  • [4]CVE-2026-105849 Record

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•about 2 hours ago•CVE-2026-86540
8.5

CVE-2026-86540: Arbitrary Code Execution via LSP Binary Override in knowns

CVE-2026-86540 is a high-severity arbitrary code execution vulnerability in knowns, a repository management tool. The vulnerability occurs when the application parses and executes unvalidated language server binary overrides defined within a project's local configuration file.

Amit Schendel
Amit Schendel
5 views•5 min read
•about 3 hours ago•CVE-2026-105854
8.7

CVE-2026-105854: Regular Expression Denial of Service (ReDoS) and Uncontrolled Resource Consumption in Payload CMS

Payload CMS, a popular open-source headless Content Management System, contains a critical Regular Expression Denial of Service (ReDoS) and uncontrolled resource consumption vulnerability in versions prior to 3.90.0 and canary versions prior to 4.0.0-canary.34. Due to nested quantifiers in the multipart boundary regex validation pattern, and the absence of streaming backpressure controls, remote attackers can trigger catastrophic backtracking and memory exhaustion. This blocks the single-threaded Node.js event loop, resulting in a persistent and complete Denial of Service (DoS).

Amit Schendel
Amit Schendel
4 views•6 min read
•about 4 hours ago•CVE-2026-105855
7.6

CVE-2026-105855: Privilege Escalation via Improper Access Control on Password Fields in Payload CMS

An Improper Access Control vulnerability (CWE-284) in Payload CMS prior to version 3.90.0 and 4.0.0-canary.34 allows authenticated, low-privileged users to bypass field-level access control restrictions and overwrite the password of other accounts, leading to complete account takeover and privilege escalation.

Alon Barad
Alon Barad
8 views•6 min read
•about 5 hours ago•CVE-2026-105804
5.7

CVE-2026-105804: Insecure Default PBKDF2 Password Hashing Configuration in Payload CMS

Payload CMS was discovered to use an insecure default configuration for its password-hashing mechanism. The system requested a 512-byte key from PBKDF2-HMAC-SHA256 with 25,000 iterations, creating a severe cryptographic asymmetry. While the defending server sequentially computed 16 blocks of key material (equivalent to 400,000 internal iterations), an offline attacker only needed to compute the first 32-byte block to verify password guesses. This allowed offline attackers to crack stolen database hashes 16 times faster than intended by the security design.

Alon Barad
Alon Barad
6 views•6 min read
•about 6 hours ago•GHSA-WQ5F-XC86-PV6W
7.8

CVE-2026-96889: Remote Code Execution via Use-After-Free in librsvg (VectorFreed)

VectorFreed identifies a critical Use-After-Free (UAF) memory corruption vulnerability in librsvg (CVE-2026-96889), which manifests when parsing structured SVG documents containing nested XML inclusions (XIncludes) and duplicate entity declarations. The flaw results from an entity ownership conflict where librsvg prematurely deallocates an xmlEntity structure still actively referenced by the underlying libxml2 parser context. When transitively compiled into downstream applications such as the high-performance sharp image processing library, this vulnerability facilitates denial of service and unauthenticated remote code execution on the host operating system.

Amit Schendel
Amit Schendel
6 views•8 min read
•about 8 hours ago•CVE-2026-102275
6.5

CVE-2026-102275: Public/Private Key Identity Confusion in PyJWT OKP JWK Processing

CVE-2026-102275 (GHSA-x33g-cr3x-6449) is a public/private key identity confusion vulnerability in PyJWT versions 2.1.0 through 2.14.0. When importing Octet Key Pair (OKP) JSON Web Keys (JWKs) representing Ed25519 or Ed448 curves, PyJWT fails to verify that the public parameter 'x' matches the private parameter 'd'. An attacker can construct a hybrid JWK combining a victim's public key with the attacker's private key. In protocols like DPoP that bind sessions via public key thumbprints, this allows the attacker to authenticate as the victim while signing proofs with their own private key, fully bypassing sender-constrained security guarantees.

Amit Schendel
Amit Schendel
7 views•6 min read