CVE-2026-105860: Payload has a tenant authorization bypass in Multi-Tenant Plugin
## Impact When using the default tenant array field access, an authenticated user could assign themselves to other tenants. **You are affected if:** - You are using `@payloadcms/plugin-multi-tenant` If you configure the tenants arrayFieldAccess.create/update functions, a secured replacement membership field, you are not affected by this specific default behavior. ## Patches Users should upgrade Payload packages to `>= 3.90.0` or `>= 4.0.0-canary.34`. ## Workarounds Configure tenants arrayFieldAccess.create and tenants arrayFieldAccess.update so only trusted users authorized for all tenants can modify memberships.
Recommended action
Recommended action
Upgrade affected packages to a patched version: @payloadcms/plugin-multi-tenant 3.90.0, @payloadcms/plugin-multi-tenant 4.0.0-canary.34.
Technical details
- Vendor
- Not specified
- Product
- @payloadcms/plugin-multi-tenant
- Exploitation
- none known
- Evidence
- official
Evidence and sources
This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source