<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Plugin-Mcp (&gt;= 3.61.0, &lt; 3.88.0) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/plugin-mcp--3.61.0--3.88.0/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 06 Oct 2026 18:48:00 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/plugin-mcp--3.61.0--3.88.0/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Improper Access Control in Payload CMS MCP Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-10-payload-mcp-access-control/</link><pubDate>Tue, 06 Oct 2026 18:48:00 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-payload-mcp-access-control/</guid><description>An improper access control vulnerability (CVE-2026-105806) in the @payloadcms/plugin-mcp package allows authenticated users to manage API keys across accounts, facilitating privilege escalation and account takeover.</description><content:encoded><![CDATA[<p>The @payloadcms/plugin-mcp package for Payload CMS is affected by an improper access control vulnerability, tracked as CVE-2026-105806, impacting versions 3.61.0 through 3.87.9. This vulnerability allows an already authenticated user to interact with and manage Model Context Protocol (MCP) API keys belonging to accounts other than their own. By manipulating requests to the API key management endpoints, an attacker can hijack these keys, potentially leading to unauthorized access, further privilege escalation, and full account takeover within the Payload CMS environment. The issue stems from insufficient validation of ownership or permission boundaries during API key management operations. Defenders should prioritize patching, as this flaw directly undermines the security boundaries between users in a multi-tenant or collaborative CMS deployment.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability allows unauthorized management of security credentials (API keys) across different user accounts within the same Payload CMS instance. If exploited, an attacker can gain control over administrative or higher-privileged API keys, leading to complete account takeover, exfiltration of sensitive CMS data, or unauthorized configuration changes. The impact is significant for organizations relying on the MCP plugin for automated workflows and integrations.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade the @payloadcms/plugin-mcp package to version 3.88.0 or later immediately to patch CVE-2026-105806.</li>
<li>If immediate patching is not feasible, disable the MCP plugin functionality until the upgrade is performed.</li>
<li>Audit logs for the API key management endpoints in Payload CMS to identify unauthorized access attempts or unusual patterns involving key manipulation from non-administrative users.</li>
<li>Restrict access to MCP API-key management interfaces to a highly limited set of trusted users until the software is updated.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>privilege-escalation</category><category>cms</category><category>web-application</category></item></channel></rss>