{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3apayloadpayloadcms_plugin_multi_tenant/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:payload:payloadcms_plugin_multi_tenant:*:*:*:*:*:*:*:*"],"_cs_cves":[{"id":"CVE-2026-105860"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["@payloadcms/plugin-multi-tenant (\u003c 3.90.0, \u003e= 4.0.0-canary.0 \u003c 4.0.0-canary.34)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","privilege-escalation","cms"],"_cs_type":"advisory","_cs_vendors":["Payload"],"content_html":"\u003cp\u003eThe Payload Multi-Tenant plugin contains an authorization bypass vulnerability (CVE-2026-105860) that permits authenticated users to manipulate tenant assignments. The vulnerability exists within the default tenant array field access configuration. By default, the plugin lacks sufficient restrictions on the 'create' and 'update' functions for the tenants array field, allowing a standard user to modify their own tenant membership. An attacker could exploit this to gain unauthorized access to other tenants, leading to horizontal or vertical privilege escalation. The issue is resolved in version 3.90.0 and version 4.0.0-canary.34. Organizations using the plugin must ensure they implement custom \u003ccode\u003earrayFieldAccess\u003c/code\u003e configurations if they cannot upgrade immediately to enforce proper membership validation.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an authenticated user to gain access to tenants they are not authorized to manage or view. This results in unauthorized data access and potential privilege escalation within the multi-tenant application environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade \u003ccode\u003e@payloadcms/plugin-multi-tenant\u003c/code\u003e to version 3.90.0 or later, or 4.0.0-canary.34 or later to address CVE-2026-105860.\u003c/li\u003e\n\u003cli\u003eIf upgrading is not immediately feasible, configure custom \u003ccode\u003etenants arrayFieldAccess.create\u003c/code\u003e and \u003ccode\u003etenants arrayFieldAccess.update\u003c/code\u003e functions to restrict modifications to users explicitly authorized for all relevant tenants.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-07T22:49:32Z","date_published":"2026-10-07T22:49:32Z","id":"https://feed.craftedsignal.io/briefs/2026-10-payload-auth-bypass/","summary":"An authorization vulnerability in @payloadcms/plugin-multi-tenant allows authenticated users to assign themselves to unauthorized tenants by leveraging default field access configurations.","title":"Authorization Bypass in @payloadcms/plugin-multi-tenant","url":"https://feed.craftedsignal.io/briefs/2026-10-payload-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:payload:payloadcms_plugin_multi_tenant:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}