CVE-2026-105860: Payload has a tenant authorization bypass in Multi-Tenant Plugin
When using the default tenant array field access, an authenticated user could assign themselves to other tenants.
You are affected if:
- You are using
@payloadcms/plugin-multi-tenant
If you configure the tenants arrayFieldAccess.create/update functions, a secured replacement membership field, you are not affected by this specific default behavior.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-105860 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →