@payloadcms/plugin-multi-tenant, Cross-Tenant Create, CVE-2026-105864 (Moderate) -DC-Oct2026-2845

Listen to this Post

The CVE-2026-105864 vulnerability resides in the `@payloadcms/plugin-multi-tenant` package used within Payload CMS. Specifically, in versions prior to 3.90.0 and canary versions before 4.0.0-canary.34, an authorization flaw allows an authenticated user who is restricted to a single tenant to bypass intended isolation barriers and create records inside an entirely different, unauthorized tenant collection. This issue stems from a lack of strict contextual verification during record creation flows when at least one tenant-enabled collection is configured. While direct reads and edits on existing cross-tenant documents remain properly protected, the write operation for creation fails validation checks. Attackers leveraging this flaw can pollute foreign tenant namespaces, inject unintended data records, and compromise multi-tenant data segregation models. Remediation requires upgrading affected packages to version 3.90.0 or 4.0.0-canary.34, or implementing explicit access control rules using `accessResultOverride` configurations.

DailyCVE Form:

Platform: Payload CMS
Version: < 3.90.0
Vulnerability: Cross-tenant create
Severity: Moderate
date: 2026-10-06

Prediction: 2026-10-06

What Undercode Say

Bash Commands and Codes

npm install @payloadcms/plugin-multi-tenant@latest
export default buildConfig({
plugins: [
multiTenantPlugin({
collections: {
pages: {
accessResultOverride: ({ req }) => {
return Boolean(req.user)
},
},
},
}),
],
})

Exploit: (Educational Purposes!)

POST /api/posts HTTP/1.1
Host: target-app.com
Content-Type: application/json
{
"": "Unauthorized Cross-Tenant Record",
"tenant": "foreign-tenant-id-xyz"
}

Protection

Upgrade affected packages immediately to version 3.90.0 or 4.0.0-canary.34. Alternatively, enforce strict validation rules by implementing access control with `accessResultOverride` on your multi-tenant collection configurations.

Impact

Authenticated users restricted to a single tenant can maliciously inject and create new records within isolated foreign tenant partitions, violating enterprise data privacy boundaries and data integrity guarantees.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top