CVE-2026-105849

Source
https://cve.org/CVERecord?id=CVE-2026-105849
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-105849.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-105849
Aliases
Published
2026-10-06T16:09:49Z
Modified
2026-10-07T02:47:59Z
Severity
  • 7.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Payload: API key disclosure through ordinary document reads
Details

Payload is a free and open source headless content management system. In versions from 3.0.0 before 3.90.0 and canary versions before 4.0.0-canary.34, users with ordinary read access to other authentication documents in a collection with useAPIKey enabled can obtain active API keys and exercise the target accounts' permissions until those keys are rotated or disabled. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-201",
        "CWE-862"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/105xxx/CVE-2026-105849.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "4.0.0-canary.0"
                },
                {
                    "fixed": "4.0.0-canary.34"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/payloadcms/payload

Affected ranges

Type
GIT
Repo
https://github.com/payloadcms/payload
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "3.0.0"
        },
        {
            "fixed": "3.90.0"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

eslint/3.*
eslint/3.0.0
eslint/3.28.0
eslint/3.9.0
v3.*
v3.0.0
v3.0.1
v3.0.2
v3.1.0
v3.1.1
v3.10.0
v3.11.0
v3.12.0
v3.13.0
v3.14.0
v3.15.0
v3.15.1
v3.16.0
v3.17.0
v3.17.1
v3.18.0
v3.19.0
v3.2.0
v3.2.1
v3.2.2
v3.20.0
v3.21.0
v3.22.0
v3.23.0
v3.24.0
v3.25.0
v3.26.0
v3.27.0
v3.28.0
v3.28.1
v3.29.0
v3.3.0
v3.30.0
v3.31.0
v3.32.0
v3.33.0
v3.34.0
v3.35.0
v3.35.1
v3.36.0
v3.36.1
v3.37.0
v3.38.0
v3.39.0
v3.39.1
v3.4.0
v3.40.0
v3.41.0
v3.42.0
v3.43.0
v3.44.0
v3.45.0
v3.46.0
v3.47.0
v3.48.0
v3.49.0
v3.49.1
v3.5.0
v3.50.0
v3.51.0
v3.52.0
v3.53.0
v3.54.0
v3.55.0
v3.55.1
v3.56.0
v3.57.0
v3.58.0
v3.59.0
v3.59.1
v3.6.0
v3.60.0
v3.61.0
v3.61.1
v3.62.0
v3.63.0
v3.64.0
v3.65.0
v3.66.0
v3.67.0
v3.68.0
v3.68.1
v3.68.2
v3.68.3
v3.68.4
v3.68.5
v3.69.0
v3.7.0
v3.70.0
v3.71.0
v3.71.1
v3.72.0
v3.73.0
v3.74.0
v3.75.0
v3.76.0
v3.76.1
v3.77.0
v3.78.0
v3.79.0
v3.79.1
v3.8.0
v3.80.0
v3.81.0
v3.82.0
v3.82.1
v3.83.0
v3.84.0
v3.84.1
v3.85.0
v3.85.1
v3.85.2
v3.86.0
v3.87.0
v3.87.1
v3.88.0
v3.89.0
v3.9.0

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-105849.json"