Under certain conditions, an authenticated user could manage MCP API keys outside their intended account allowing an attacker to escalate privileges through account takeover.
Applications that do not use @payloadcms/plugin-mcp are not affected.
Users should upgrade to @payloadcms/plugin-mcp version 3.88.0 or later.
Upgrading is recommended. Until then, disable the MCP plugin or restrict MCP API-key management to trusted users.
{
"cwe_ids": [
"CWE-862"
],
"github_reviewed": true,
"github_reviewed_at": "2026-10-06T16:09:31Z",
"nvd_published_at": null,
"severity": "HIGH"
}