GHSA-p96c-xwx8-3cqjHigh

Payload has a tenant authorization bypass in Multi-Tenant Plugin

Published
October 7, 2026
Last Modified
October 7, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact

When using the default tenant array field access, an authenticated user could assign themselves to other tenants.

You are affected if:

  • You are using @payloadcms/plugin-multi-tenant

If you configure the tenants arrayFieldAccess.create/update functions, a secured replacement membership field, you are not affected by this specific default behavior.

Patches

Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.

Workarounds

Configure tenants arrayFieldAccess.create and tenants arrayFieldAccess.update so only trusted users authorized for all tenants can modify memberships.

🎯 Affected products2

  • npm/@payloadcms/plugin-multi-tenant:< 3.90.0
  • npm/@payloadcms/plugin-multi-tenant:>= 4.0.0-canary.0, < 4.0.0-canary.34

🔗 References (5)