PT-2026-106793 · Payloadcms · @Payloadcms/Plugin-Multi-Tenant
CVE-2026-105860
·
Published
2026-10-06
·
Updated
2026-10-07
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
@payloadcms/plugin-multi-tenant versions prior to 3.90.0
@payloadcms/plugin-multi-tenant canary versions prior to 4.0.0-canary.34
Description
An authenticated user can assign their own account to other tenants due to the default tenant array field access. This issue does not affect deployments that have replaced the default behavior with secured
tenants arrayFieldAccess.create and tenants arrayFieldAccess.update functions.Recommendations
Update @payloadcms/plugin-multi-tenant to version 3.90.0 or later.
Update @payloadcms/plugin-multi-tenant canary to version 4.0.0-canary.34 or later.
As a mitigation measure, replace the default behavior with secured
tenants arrayFieldAccess.create and tenants arrayFieldAccess.update functions.Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
@Payloadcms/Plugin-Multi-Tenant