Listen to this Post
The CVE-2026-105864 vulnerability resides in the `@payloadcms/plugin-multi-tenant` package used within Payload CMS. Specifically, in versions prior to 3.90.0 and canary versions before 4.0.0-canary.34, an authorization flaw allows an authenticated user who is restricted to a single tenant to bypass intended isolation barriers and create records inside an entirely different, unauthorized tenant collection. This issue stems from a lack of strict contextual verification during record creation flows when at least one tenant-enabled collection is configured. While direct reads and edits on existing cross-tenant documents remain properly protected, the write operation for creation fails validation checks. Attackers leveraging this flaw can pollute foreign tenant namespaces, inject unintended data records, and compromise multi-tenant data segregation models. Remediation requires upgrading affected packages to version 3.90.0 or 4.0.0-canary.34, or implementing explicit access control rules using `accessResultOverride` configurations.
DailyCVE Form:
Platform: Payload CMS
Version: < 3.90.0
Vulnerability: Cross-tenant create
Severity: Moderate
date: 2026-10-06
Prediction: 2026-10-06
What Undercode Say
Bash Commands and Codes
npm install @payloadcms/plugin-multi-tenant@latest
export default buildConfig({
plugins: [
multiTenantPlugin({
collections: {
pages: {
accessResultOverride: ({ req }) => {
return Boolean(req.user)
},
},
},
}),
],
})
Exploit: (Educational Purposes!)
POST /api/posts HTTP/1.1
Host: target-app.com
Content-Type: application/json
{
"": "Unauthorized Cross-Tenant Record",
"tenant": "foreign-tenant-id-xyz"
}
Protection
Upgrade affected packages immediately to version 3.90.0 or 4.0.0-canary.34. Alternatively, enforce strict validation rules by implementing access control with `accessResultOverride` on your multi-tenant collection configurations.
Impact
Authenticated users restricted to a single tenant can maliciously inject and create new records within isolated foreign tenant partitions, violating enterprise data privacy boundaries and data integrity guarantees.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

