OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2026-105860: Payload has a tenant authorization bypass in Multi-Tenant Plugin

GitHub Advisories · officialPublished Oct 7, 2026Risk 37/100

## Impact When using the default tenant array field access, an authenticated user could assign themselves to other tenants. **You are affected if:** - You are using `@payloadcms/plugin-multi-tenant` If you configure the tenants arrayFieldAccess.create/update functions, a secured replacement membership field, you are not affected by this specific default behavior. ## Patches Users should upgrade Payload packages to `>= 3.90.0` or `>= 4.0.0-canary.34`. ## Workarounds Configure tenants arrayFieldAccess.create and tenants arrayFieldAccess.update so only trusted users authorized for all tenants can modify memberships.

Upgrade affected packages to a patched version: @payloadcms/plugin-multi-tenant 3.90.0, @payloadcms/plugin-multi-tenant 4.0.0-canary.34.

Vendor
Not specified
Product
@payloadcms/plugin-multi-tenant
Exploitation
none known
Evidence
official

This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source