GHSA-p96c-xwx8-3cqjHigh
Payload has a tenant authorization bypass in Multi-Tenant Plugin
🔗 CVE IDs covered (1)
📋 Description
Impact
When using the default tenant array field access, an authenticated user could assign themselves to other tenants.
You are affected if:
- You are using
@payloadcms/plugin-multi-tenant
If you configure the tenants arrayFieldAccess.create/update functions, a secured replacement membership field, you are not affected by this specific default behavior.
Patches
Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.
Workarounds
Configure tenants arrayFieldAccess.create and tenants arrayFieldAccess.update so only trusted users authorized for all tenants can modify memberships.
🎯 Affected products2
- npm/@payloadcms/plugin-multi-tenant:< 3.90.0
- npm/@payloadcms/plugin-multi-tenant:>= 4.0.0-canary.0, < 4.0.0-canary.34
🔗 References (5)
- https://github.com/payloadcms/payload/security/advisories/GHSA-p96c-xwx8-3cqj
- https://nvd.nist.gov/vuln/detail/CVE-2026-105860
- https://github.com/payloadcms/payload/commit/19b58692d20d3947f31124bf7a88ac14a5ebf02e
- https://github.com/payloadcms/payload/releases/tag/v3.90.0
- https://github.com/advisories/GHSA-p96c-xwx8-3cqj