When using the default tenant array field access, an authenticated user could assign themselves to other tenants.
You are affected if:
@payloadcms/plugin-multi-tenantIf you configure the tenants arrayFieldAccess.create/update functions, a secured replacement membership field, you are not affected by this specific default behavior.
Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.
Configure tenants arrayFieldAccess.create and tenants arrayFieldAccess.update so only trusted users authorized for all tenants can modify memberships.
{
"cwe_ids": [
"CWE-862"
],
"github_reviewed": true,
"github_reviewed_at": "2026-10-07T20:29:53Z",
"nvd_published_at": "2026-10-06T17:17:22Z",
"severity": "HIGH"
}