GHSA-xhm9-gwgw-3q2q: Npm/@payloadcms/plugin-multi-tenant vulnerability

Published Oct 7, 2026
·
Updated

Impact An authenticated user limited to one tenant could create a record in another tenant. This requires the multi-tenant plugin with at least one tenant-enabled collection.

Reads and direct edits to an existing target-tenant document were not bypassed.

You are affected if: - You are using @payloadcms/plugin-multi-tenant

Patches Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.

Workarounds You can add access control with accessResultOverride on the multi-tenant collection config to ensure a user has access to the tenant before creating.

Affected Software

2 affected componentsFixes available
npm/@payloadcms/plugin-multi-tenant>=4.0.0-canary.0<4.0.0-canary.34
4.0.0-canary.34
npm/@payloadcms/plugin-multi-tenant<3.90.0
3.90.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/@payloadcms/plugin-multi-tenant to a version that resolves this vulnerability.

    Fixed in 4.0.0-canary.34
  2. Upgrade

    Upgrade npm/@payloadcms/plugin-multi-tenant to a version that resolves this vulnerability.

    Fixed in 3.90.0
  3. Upgrade

    Upgrade @payloadcms/plugin-multi-tenant to a version that resolves this vulnerability.

    Fixed in 3.90.0
  4. Upgrade

    Upgrade @payloadcms/plugin-multi-tenant to a version that resolves this vulnerability.

    Fixed in 4.0.0-canary.34
  5. Configuration

    Configure accessResultOverride on the multi-tenant collection to ensure a user has access to the tenant before creating a record.

    @payloadcms/plugin-multi-tenant accessResultOverride = require tenant access before creation

Event History

Oct 7, 2026
Advisory Published
via GitHub·08:29 PM
Data Sourced
via GitHub·08:29 PM
DescriptionWeaknessAffected Software

Frequently Asked Questions

1

Who is exposed to this issue?

Deployments using @payloadcms/plugin-multi-tenant with at least one tenant-enabled collection are affected. The issue applies to authenticated users who are restricted to a single tenant.

2

What can an attacker do, and what access do they need?

An authenticated user limited to one tenant can create a record in another tenant. The issue does not bypass reads or direct edits to existing documents in the target tenant.

3

Which versions contain a fix?

Upgrade Payload packages to version 3.90.0 or later, or to 4.0.0-canary.34 or later.

4

What can be done if upgrading is not immediately possible?

Add access control using accessResultOverride in the multi-tenant collection configuration. This should verify that the user has access to the tenant before allowing record creation.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203