Authorization Bypass in @payloadcms/plugin-multi-tenant
An authorization vulnerability in @payloadcms/plugin-multi-tenant allows authenticated users to assign themselves to unauthorized tenants by leveraging default field access configurations.
CVE search metadata
CVE search record: CVE-2026-105860. KEV: no. Product: @payloadcms/plugin-multi-tenant (< 3.90.0, >= 4.0.0-canary.0 < 4.0.0-canary.34). Brief: Authorization Bypass in @payloadcms/plugin-multi-tenant. Brief link: https://feed.craftedsignal.io/briefs/2026-10-payload-auth-bypass/
The Payload Multi-Tenant plugin contains an authorization bypass vulnerability (CVE-2026-105860) that permits authenticated users to manipulate tenant assignments. The vulnerability exists within the default tenant array field access configuration. By default, the plugin lacks sufficient restrictions on the 'create' and 'update' functions for the tenants array field, allowing a standard user to modify their own tenant membership. An attacker could exploit this to gain unauthorized access to other tenants, leading to horizontal or vertical privilege escalation. The issue is resolved in version 3.90.0 and version 4.0.0-canary.34. Organizations using the plugin must ensure they implement custom arrayFieldAccess configurations if they cannot upgrade immediately to enforce proper membership validation.
Impact
Successful exploitation allows an authenticated user to gain access to tenants they are not authorized to manage or view. This results in unauthorized data access and potential privilege escalation within the multi-tenant application environment.
Recommendation
- Upgrade
@payloadcms/plugin-multi-tenantto version 3.90.0 or later, or 4.0.0-canary.34 or later to address CVE-2026-105860. - If upgrading is not immediately feasible, configure custom
tenants arrayFieldAccess.createandtenants arrayFieldAccess.updatefunctions to restrict modifications to users explicitly authorized for all relevant tenants.
Immediate actions
Upgrade @payloadcms/plugin-multi-tenant to 3.90.0 or 4.0.0-canary.34
Mitigations
Configure custom tenants arrayFieldAccess.create/update functions to restrict membership modification
CVE-2026-105860