Product
An authorization vulnerability in @payloadcms/plugin-multi-tenant allows authenticated users to assign themselves to unauthorized tenants by leveraging default field access configurations.