PT-2026-106793 · Payloadcms · @Payloadcms/Plugin-Multi-Tenant

CVE-2026-105860

·

Published

2026-10-06

·

Updated

2026-10-07

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions @payloadcms/plugin-multi-tenant versions prior to 3.90.0 @payloadcms/plugin-multi-tenant canary versions prior to 4.0.0-canary.34
Description An authenticated user can assign their own account to other tenants due to the default tenant array field access. This issue does not affect deployments that have replaced the default behavior with secured tenants arrayFieldAccess.create and tenants arrayFieldAccess.update functions.
Recommendations Update @payloadcms/plugin-multi-tenant to version 3.90.0 or later. Update @payloadcms/plugin-multi-tenant canary to version 4.0.0-canary.34 or later. As a mitigation measure, replace the default behavior with secured tenants arrayFieldAccess.create and tenants arrayFieldAccess.update functions.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-105860
GHSA-P96C-XWX8-3CQJ

Affected Products

@Payloadcms/Plugin-Multi-Tenant