Impact
An ordinary document read in PayloadCMS can expose active API keys for the target collection when useAPIKey is enabled. The attacker can acquire a key that carries the full permissions of the account that owns it until the key is rotated or disabled. This flaw is an information exposure, allowing a malicious actor to use the key to perform actions on the system that the account is authorized to do, up to the permissions granted to that account.
Affected Systems
PayloadCMS from version 3.0.0 up to, but not including, 3.90.0 and all canary releases before 4.0.0-canary.34 are affected. Users of these builds with read access to authentication documents on a collection with useAPIKey enabled are at risk. Updated releases 3.90.0 and 4.0.0-canary.34 contain the fix.
Risk and Exploitability
The CVSS score of 7.7 indicates moderate to high severity. No EPSS score is provided, and the vulnerability is not listed in the CISA KEV catalog, suggesting it is not currently a known exploited target. The exploit path requires only ordinary read access with standard authentication, so an attacker who gains read privileges can retrieve the key. Once the key is in hand the attacker can act with the same authority as the account owner until the key is rotated or revoked.
OpenCVE Enrichment
Github GHSA