High severityNVD Advisory· Published Oct 6, 2026· Updated Oct 6, 2026
CVE-2026-105860
CVE-2026-105860
Description
Payload is a free and open source headless content management system. In @payloadcms/plugin-multi-tenant versions before 3.90.0 and canary versions before 4.0.0-canary.34, the default tenant array field access allows an authenticated user to assign the user's own account to other tenants. Deployments that replace the default behavior with secured tenants arrayFieldAccess.create and tenants arrayFieldAccess.update functions are not affected by this behavior. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <3.90.0, <4.0.0-canary.34
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.