Impact
The vulnerability resides in Payload CMS’s @payloadcms/plugin-multi-tenant component. In versions before 3.90.0 and canary releases before 4.0.0-canary.34, the default configuration of the tenants array field grants any authenticated user permission to assign their own account to any tenant. By exercising this functionality, the user can effectively add themselves to other tenants, escalating privileges within the multi‑tenant environment. The flaw is classified as an authorization error (CWE-862).
Affected Systems
Affected systems are installations of Payload CMS that include the @payloadcms/plugin-multi-tenant plugin. Any deployment using a stable release earlier than 3.90.0, or a canary release earlier than 4.0.0-canary.34, remains vulnerable. Deployments that have overridden the default tenants arrayFieldAccess.create and tenants arrayFieldAccess.update functions are considered non‑vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity. EPSS is not available and the vulnerability is not listed in the CISA KEV catalog, indicating no large‑scale exploitation has been reported. The flaw requires only an authenticated session and normal API calls to create or update tenant assignments, meaning that an attacker with legitimate credentials can exploit it. Updating to 3.90.0 or 4.0.0-canary.34 removes the issue; otherwise, enforcing stricter array field access control mitigates the risk.
OpenCVE Enrichment