Skip to content
Threat Feed
critical advisory updated

Payload API Key Disclosure via Document Read Access

A vulnerability in Payload CMS versions 3.x and 4.x-canary allows unauthorized users with document read permissions to access active API keys stored within authentication collections.

CVE search metadata

CVE search record: CVE-2026-105849. KEV: no. Product: payload (>= 3.0.0 < 3.90.0, >= 4.0.0-canary.0 < 4.0.0-canary.34), Payload (>= 3.0.0, < 3.90.0), Payload (>= 4.0.0-canary.0, < 4.0.0-canary.34), Payload (3.0.0 - 3.89.9), Payload (4.0.0-canary.0 - 4.0.0-canary.33), Payload (3.0.0 <= version < 3.88.0, 4.0.0-canary.0 <= version < 4.0.0-canary.27), Payload (v3.x < 3.87.0), Payload (v4.0.0-canary < 4.0.0-canary.20), Payload (< 3.90.0, >= 4.0.0-canary.0 < 4.0.0-canary.34), Payload (v3.0.0 to <3.90.0), Payload (v4.0.0-canary.0 to <4.0.0-canary.34), Payload (< 3.90.0), Payload (< 3.90.0, >= 4.0.0-canary.0, < 4.0.0-canary.34). Brief: Payload API Key Disclosure via Document Read Access. Brief link: https://feed.craftedsignal.io/briefs/2026-10-payload-api-key-disclosure/

What's new

  • 1. added coverage for Payload (< 3.90.0, >= 4.0.0-canary.0 < 4.0.0-canary.34) Oct 7, 22:50 via ghsa
  • 2. added coverage for Payload (< 3.90.0) +1 products Oct 7, 22:49 via ghsa
  • 3. added coverage for Payload (< 3.90.0, >= 4.0.0-canary.0, < 4.0.0-canary.34) Oct 7, 22:49 via ghsa
  • 4. added coverage for Payload (>= 3.0.0, < 3.90.0) +1 products Oct 7, 22:49 via ghsa
  • 5. added coverage for Payload (< 3.90.0) +1 products Oct 7, 22:49 via ghsa

Payload CMS versions prior to 3.90.0 and 4.0.0-canary.34 are vulnerable to an API key disclosure flaw, tracked as CVE-2026-105849. This vulnerability manifests in deployments where the useAPIKey authentication feature is enabled. Due to insecure access control logic, users who possess read access to documents within an authentication collection can view sensitive API keys belonging to other users. Because these keys hold the permissions of the target account, successful exploitation allows an attacker to masquerade as the compromised user until the key is rotated or disabled. This impacts organizations relying on Payload for authentication and document management, particularly those with permissive document access policies.

Impact

Successful exploitation allows unauthorized users to retrieve valid API keys of other users, leading to account takeover. The impact is significant for applications where API keys manage sensitive operations or provide access to protected administrative functions. Users must immediately verify document read permissions and rotate any keys potentially exposed during the window of vulnerability.

Recommendation

  • Upgrade Payload CMS to version 3.90.0 or 4.0.0-canary.34 to patch CVE-2026-105849.
  • Audit document read permissions in the CMS and restrict access to authentication collections to authorized users only.
  • Disable the useAPIKey feature if not strictly required for application functionality.
  • Perform a mandatory rotation of all active API keys generated while the affected versions were in use to mitigate potential unauthorized access.

Immediate actions

Upgrade Payload CMS to 3.90.0 or 4.0.0-canary.34

IT Operations 24h

Mitigations

Rotate all API keys generated under affected versions

immediate Security Team

CVE-2026-105849