Access Control Issue in Payload CMS Affects User Tenant Assignment
CVE-2026-105860
7.1HIGH
What is CVE-2026-105860?
In Payload CMS, specifically in the @payloadcms/plugin-multi-tenant before version 3.90.0 and canary versions before 4.0.0-canary.34, an authenticated user can exploit the default tenant array field access configuration. This issue allows a user to assign themselves to multiple tenants, leading to potential unauthorized access and data leakage. Deployments using secure implementations of the tenants arrayFieldAccess.create and update functions are not impacted. The vulnerability has been addressed in the latest releases.
Affected Version(s)
payload < 3.90.0 < 3.90.0
payload >= 4.0.0-canary.0, < 4.0.0-canary.34 < 4.0.0-canary.0, 4.0.0-canary.34
