GHSA-xhm9-gwgw-3q2qMedium

@payloadcms/plugin-multi-tenant has a cross-tenant create issue

Published
October 7, 2026
Last Modified
October 7, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact

An authenticated user limited to one tenant could create a record in another tenant. This requires the multi-tenant plugin with at least one tenant-enabled collection.

Reads and direct edits to an existing target-tenant document were not bypassed.

You are affected if:

  • You are using @payloadcms/plugin-multi-tenant

Patches

Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.

Workarounds

You can add access control with accessResultOverride on the multi-tenant collection config to ensure a user has access to the tenant before creating.

🎯 Affected products2

  • npm/@payloadcms/plugin-multi-tenant:< 3.90.0
  • npm/@payloadcms/plugin-multi-tenant:>= 4.0.0-canary.0, < 4.0.0-canary.34

🔗 References (5)