Access Control Issue in Payload CMS Affects User Tenant Assignment
CVE-2026-105860

7.1HIGH

Key Information:

Vendor

Payloadcms

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-105860?

In Payload CMS, specifically in the @payloadcms/plugin-multi-tenant before version 3.90.0 and canary versions before 4.0.0-canary.34, an authenticated user can exploit the default tenant array field access configuration. This issue allows a user to assign themselves to multiple tenants, leading to potential unauthorized access and data leakage. Deployments using secure implementations of the tenants arrayFieldAccess.create and update functions are not impacted. The vulnerability has been addressed in the latest releases.

Affected Version(s)

payload < 3.90.0 < 3.90.0

payload >= 4.0.0-canary.0, < 4.0.0-canary.34 < 4.0.0-canary.0, 4.0.0-canary.34

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.