CVE-2026-105860
Received Received - Intake

Privilege Escalation in Payload CMS via Tenant Assignment

Vulnerability report for CVE-2026-105860, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: GitHub, Inc.

Description

Payload is a free and open source headless content management system. In @payloadcms/plugin-multi-tenant versions before 3.90.0 and canary versions before 4.0.0-canary.34, the default tenant array field access allows an authenticated user to assign the user's own account to other tenants. Deployments that replace the default behavior with secured tenants arrayFieldAccess.create and tenants arrayFieldAccess.update functions are not affected by this behavior. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
payloadcms payload < 3.90.0
payloadcms payload >= 4.0.0-canary.0, < 4.0.0-canary.34

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Payload, a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, an authenticated user can assign their own account to other tenants due to a default tenant array field access issue. Deployments with secured tenant arrayFieldAccess functions are not affected.

Detection Guidance

Check the installed version of @payloadcms/plugin-multi-tenant. If it is before 3.90.0 or a canary version before 4.0.0-canary.34, the system is vulnerable. Review tenant assignments for authenticated users to ensure no unauthorized tenant associations exist.

Impact Analysis

An attacker with authenticated access could escalate privileges by associating their account with multiple tenants, potentially gaining unauthorized access to sensitive data across tenants. This could lead to data breaches or unauthorized modifications.

Compliance Impact

This vulnerability could violate compliance requirements such as GDPR or HIPAA by enabling unauthorized access to protected data across tenants. It may lead to data leaks, loss of data integrity, and failure to maintain proper access controls.

Mitigation Strategies

Update @payloadcms/plugin-multi-tenant to version 3.90.0 or later for stable releases, or 4.0.0-canary.34 or later for canary releases. Verify that custom tenant array field access controls are properly configured to prevent unauthorized tenant assignments.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105860. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart