CVE-2026-105860High· 7.1▾ TwilightPayload is a free and open source headless content management system. In @payloadcms/plugin-multi-tenant versions before 3.90.0 and canary versions before 4.0.0-canary.34, the default tenant array field access allows an authenticated use…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 39.1 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Payload is a free and open source headless content management system. In @payloadcms/plugin-multi-tenant versions before 3.90.0 and canary versions before 4.0.0-canary.34, the default tenant array field access allows an authenticated user to assign the user's own account to other tenants. Deployments that replace the default behavior with secured tenants arrayFieldAccess.create and tenants arrayFieldAccess.update functions are not affected by this behavior. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
payload < 3.90.0payload >= 4.0.0-canary.0, < 4.0.0-canary.34Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-105859Critical· 9.8Payload: Unauthorized update to collection documents
CVE-2026-105852Medium· 6.9Payload relationship-query authorization bypass
CVE-2026-105849High· 7.7Payload vulnerable to API key disclosure through ordinary document reads
CVE-2026-105857Critical· 10.0Payload: RCE in Payload Form Builder
CVE-2026-105856High· 8.6Payload: SQL injection in SQLite/Postgres
CVE-2026-105858High· 8.1Payload: Remote Code Execution through first-register