Description
Payload is a free and open source headless content management system. In @payloadcms/plugin-multi-tenant versions before 3.90.0 and canary versions before 4.0.0-canary.34, the default tenant array field access allows an authenticated user to assign the user's own account to other tenants. Deployments that replace the default behavior with secured tenants arrayFieldAccess.create and tenants arrayFieldAccess.update functions are not affected by this behavior. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
Published: 2026-10-06
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Tenant authorization bypass
Action: Apply patch
AI Analysis

Impact

The vulnerability resides in Payload CMS’s @payloadcms/plugin-multi-tenant component. In versions before 3.90.0 and canary releases before 4.0.0-canary.34, the default configuration of the tenants array field grants any authenticated user permission to assign their own account to any tenant. By exercising this functionality, the user can effectively add themselves to other tenants, escalating privileges within the multi‑tenant environment. The flaw is classified as an authorization error (CWE-862).

Affected Systems

Affected systems are installations of Payload CMS that include the @payloadcms/plugin-multi-tenant plugin. Any deployment using a stable release earlier than 3.90.0, or a canary release earlier than 4.0.0-canary.34, remains vulnerable. Deployments that have overridden the default tenants arrayFieldAccess.create and tenants arrayFieldAccess.update functions are considered non‑vulnerable.

Risk and Exploitability

The CVSS score of 7.1 indicates high severity. EPSS is not available and the vulnerability is not listed in the CISA KEV catalog, indicating no large‑scale exploitation has been reported. The flaw requires only an authenticated session and normal API calls to create or update tenant assignments, meaning that an attacker with legitimate credentials can exploit it. Updating to 3.90.0 or 4.0.0-canary.34 removes the issue; otherwise, enforcing stricter array field access control mitigates the risk.

Generated by OpenCVE AI on October 6, 2026 at 18:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade @payloadcms/plugin-multi-tenant to version 3.90.0 or newer 4.0.0-canary.34, which removes the unauthorized tenant assignment flaw.
  • If an upgrade cannot be performed immediately, override the default tenants arrayFieldAccess.create and tenants arrayFieldAccess.update functions to ensure an account can only be added to tenants explicitly authorized for that account.
  • Disable the insecure default tenant array field access behavior in older releases or configure custom access functions to reject any assignment that does not match the authenticated user's current tenant list.
  • Perform a security review of any custom tenancy logic to confirm that there are no remaining paths allowing privilege escalation through tenant assignment.

Generated by OpenCVE AI on October 6, 2026 at 18:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 16:45:00 +0000

Type Values Removed Values Added
Description Payload is a free and open source headless content management system. In @payloadcms/plugin-multi-tenant versions before 3.90.0 and canary versions before 4.0.0-canary.34, the default tenant array field access allows an authenticated user to assign the user's own account to other tenants. Deployments that replace the default behavior with secured tenants arrayFieldAccess.create and tenants arrayFieldAccess.update functions are not affected by this behavior. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
Title Payload: Tenant authorization bypass in Multi-Tenant Plugin
Weaknesses CWE-862
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-06T17:15:03.137Z

Reserved: 2026-10-05T23:06:29.748Z

Link: CVE-2026-105860

cve-icon Vulnrichment

Updated: 2026-10-06T17:14:35.368Z

cve-icon NVD

Status : Received

Published: 2026-10-06T17:17:22.133

Modified: 2026-10-06T18:16:49.440

Link: CVE-2026-105860

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T18:30:05Z

Weaknesses