Payload: Improper access control for MCP API keys
Under certain conditions, an authenticated user could manage MCP API keys outside their intended account allowing an attacker to escalate privileges through account takeover. Applications that do not use @payloadcms/plugin-mcp are not affected.