๐Ÿ” CVE Alert

CVE-2026-105864

UNKNOWN 0.0

Payload: Cross-tenant create in @payloadcms/plugin-multi-tenant

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Payload is a free and open source headless content management system. In @payloadcms/plugin-multi-tenant versions before 3.90.0 and canary versions before 4.0.0-canary.34, an authenticated user limited to one tenant can create a record in another tenant when at least one tenant-enabled collection exists. Reads and direct edits of existing documents in the target tenant are not bypassed. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.

CWE CWE-863
Vendor payloadcms
Product payload
Published Oct 6, 2026
Last Updated Oct 6, 2026
Stay Ahead of the Next One

Get instant alerts for payloadcms payload

Be the first to know when new unknown vulnerabilities affecting payloadcms payload are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

payloadcms / payload
< 3.90.0 >= 4.0.0-canary.0, < 4.0.0-canary.34
@payloadcms / plugin-multi-tenant
< 3.90.0 >= 4.0.0-canary.0, < 4.0.0-canary.34

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/payloadcms/payload/security/advisories/GHSA-xhm9-gwgw-3q2q github.com: https://github.com/payloadcms/payload/commit/b8fc06a18afb6974dc07f95ac1e541c716e5926b github.com: https://github.com/payloadcms/payload/releases/tag/v3.90.0