Impact
When using the default tenant array field access, an authenticated user could assign themselves to other tenants.
You are affected if:
- You are using @payloadcms/plugin-multi-tenant
If you configure the tenants arrayFieldAccess.create/update functions, a secured replacement membership field, you are not affected by this specific default behavior.
Patches
Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.
Workarounds
Configure tenants arrayFieldAccess.create and tenants arrayFieldAccess.update so only trusted users authorized for all tenants can modify memberships.
Impact An authenticated user limited to one tenant could create a record in another tenant. This requires the multi-tenant plugin with at least one tenant-enabled collection.
Reads and direct edits to an existing target-tenant document were not bypassed.
You are affected if: - You are using @payloadcms/plugin-multi-tenant
Patches Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.
Workarounds You can add access control with accessResultOverride on the multi-tenant collection config to ensure a user has access to the tenant before creating.