Vulnerability GHSA-xhm9-gwgw-3q2q
Medium Risk
MEDIUM RISK
CVSS Score: 6.0
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
7 hours ago
October 07, 2026 at 08:29 PM UTC
@payloadcms/plugin-multi-tenant has a cross-tenant create issue
0.0.1 - 3.89.0 and 4.0.0-canary.0 - 4.0.0-canary.33
0.0.1 - 3.89.0 and 4.0.0-canary.0 - 4.0.0-canary.33
Summary
@payloadcms/plugin-multi-tenant has a cross-tenant create issue
Details
Impact
An authenticated user limited to one tenant could create a record in another tenant. This requires the multi-tenant plugin with at least one tenant-enabled collection.
Reads and direct edits to an existing target-tenant document were not bypassed.
You are affected if:
- You are using @payloadcms/plugin-multi-tenant
Patches
Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.
Workarounds
You can add access control with accessResultOverride on the multi-tenant collection config to ensure a user has access to the tenant before creating.
Impacted packages
Timeline
Published
7 hours ago
October 07, 2026 at 08:29 PM UTC
Fixed (3.90.0)
19 days ago
September 18, 2026 at 02:22 PM UTC
Fixed (4.0.0-canary.34)
19 days ago
September 18, 2026 at 02:29 PM UTC
Last Modified
7 hours ago
October 07, 2026 at 08:45 PM UTC