CVE-2026-105860: high-severity vulnerability in payloadcms payload
Payload: Tenant authorization bypass in Multi-Tenant Plugin
Published
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.1epss 0.2%
exploitation probability
0.2%top 86% of all CVEs
observed exploitation
nono source reports it
Payload is a free and open source headless content management system. In @payloadcms/plugin-multi-tenant versions before 3.90.0 and canary versions before 4.0.0-canary.34, the default tenant array field access allows an authenticated user to assign the user's own account to other tenants. Deployments that replace the default behavior with secured tenants arrayFieldAccess.create and tenants arrayFieldAccess.update functions are not affected by this behavior. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Affected products
payloadcms · payloadRelated CVEs — payloadcms payload
In the same product, most dangerous first.
CVE-2026-25544CRITICALPayload has an SQL Injection in JSON/RichText Queries on PostgreSQL/SQLite AdaptersEPSS 1.0%CVE-2023-30843HIGHPayload's hidden fields can be leaked on readable collectionsEPSS 0.6%CVE-2026-105844CRITICALPayload: Prototype pollution in Payload Import Export pluginEPSS 0.5%CVE-2026-105858HIGHPayload: Remote Code Execution through first-registerEPSS 0.5%CVE-2026-105857CRITICALPayload: RCE in Payload Form BuilderEPSS 0.4%CVE-2026-34751CRITICALPayload has Unvalidated Input in Password Recovery EndpointsEPSS 0.4%