CVE-2026-105806 - Payload: Improper access control for MCP API keys
CVE ID :CVE-2026-105806 Published : Oct. 6, 2026, 4:17 p.m. | 1 hour, 11 minutes ago Description :Payload is a free and open source headless content management system. In @payloadcms/plugin-mcp versions from 3.61.0 until 3.88.0, an authenticated user can manage MCP API keys outside the...