GHSA-xhm9-gwgw-3q2qMedium
@payloadcms/plugin-multi-tenant has a cross-tenant create issue
🔗 CVE IDs covered (1)
📋 Description
Impact
An authenticated user limited to one tenant could create a record in another tenant. This requires the multi-tenant plugin with at least one tenant-enabled collection.
Reads and direct edits to an existing target-tenant document were not bypassed.
You are affected if:
- You are using @payloadcms/plugin-multi-tenant
Patches
Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.
Workarounds
You can add access control with accessResultOverride on the multi-tenant collection config to ensure a user has access to the tenant before creating.
🎯 Affected products2
- npm/@payloadcms/plugin-multi-tenant:< 3.90.0
- npm/@payloadcms/plugin-multi-tenant:>= 4.0.0-canary.0, < 4.0.0-canary.34
🔗 References (5)
- https://github.com/payloadcms/payload/security/advisories/GHSA-xhm9-gwgw-3q2q
- https://nvd.nist.gov/vuln/detail/CVE-2026-105864
- https://github.com/payloadcms/payload/commit/b8fc06a18afb6974dc07f95ac1e541c716e5926b
- https://github.com/payloadcms/payload/releases/tag/v3.90.0
- https://github.com/advisories/GHSA-xhm9-gwgw-3q2q