<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>@Payloadcms/Plugin-Multi-Tenant (&lt; 3.90.0, &gt;= 4.0.0-Canary.0 &lt; 4.0.0-Canary.34) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/@payloadcms/plugin-multi-tenant--3.90.0--4.0.0-canary.0--4.0.0-canary.34/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 07 Oct 2026 22:49:32 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/@payloadcms/plugin-multi-tenant--3.90.0--4.0.0-canary.0--4.0.0-canary.34/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Authorization Bypass in @payloadcms/plugin-multi-tenant</title><link>https://feed.craftedsignal.io/briefs/2026-10-payload-auth-bypass/</link><pubDate>Wed, 07 Oct 2026 22:49:32 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-payload-auth-bypass/</guid><description>An authorization vulnerability in @payloadcms/plugin-multi-tenant allows authenticated users to assign themselves to unauthorized tenants by leveraging default field access configurations.</description><content:encoded><![CDATA[<p>The Payload Multi-Tenant plugin contains an authorization bypass vulnerability (CVE-2026-105860) that permits authenticated users to manipulate tenant assignments. The vulnerability exists within the default tenant array field access configuration. By default, the plugin lacks sufficient restrictions on the 'create' and 'update' functions for the tenants array field, allowing a standard user to modify their own tenant membership. An attacker could exploit this to gain unauthorized access to other tenants, leading to horizontal or vertical privilege escalation. The issue is resolved in version 3.90.0 and version 4.0.0-canary.34. Organizations using the plugin must ensure they implement custom <code>arrayFieldAccess</code> configurations if they cannot upgrade immediately to enforce proper membership validation.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows an authenticated user to gain access to tenants they are not authorized to manage or view. This results in unauthorized data access and potential privilege escalation within the multi-tenant application environment.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade <code>@payloadcms/plugin-multi-tenant</code> to version 3.90.0 or later, or 4.0.0-canary.34 or later to address CVE-2026-105860.</li>
<li>If upgrading is not immediately feasible, configure custom <code>tenants arrayFieldAccess.create</code> and <code>tenants arrayFieldAccess.update</code> functions to restrict modifications to users explicitly authorized for all relevant tenants.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>privilege-escalation</category><category>cms</category></item></channel></rss>