PT-2026-106768 · Payloadcms · @Payloadcms/Plugin-Mcp
CVE-2026-105806
·
Published
2026-10-06
·
Updated
2026-10-06
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
@payloadcms/plugin-mcp versions 3.61.0 through 3.87.0
Description
An authenticated user can manage MCP API keys outside the intended account, which allows for privilege escalation through account takeover.
Recommendations
Update @payloadcms/plugin-mcp to version 3.88.0 or later.
Disable the MCP plugin as a temporary mitigation.
Restrict MCP API-key management to trusted users.
Exploit
Fix
LPE
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
@Payloadcms/Plugin-Mcp