---
id: CVE-2026-105860
title: Payload is a free and open source headless content management system
summary: >-
  Payload is a free and open source headless content management system. In
  @payloadcms/plugin-multi-tenant versions before 3.90.0 and canary versions
  before 4.0.0-canary.34, the default tenant array field access allows an
  authenticated use…
severity: high
cvss: 7.1
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'
cwe:
  - CWE-862
vendor: payloadcms
product: payload
affected:
  - payload < 3.90.0
  - 'payload >= 4.0.0-canary.0, < 4.0.0-canary.34'
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T18:16:49.440'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-105860'
references:
  - url: >-
      https://github.com/payloadcms/payload/commit/19b58692d20d3947f31124bf7a88ac14a5ebf02e
    label: security-advisories@github.com
  - url: 'https://github.com/payloadcms/payload/releases/tag/v3.90.0'
    label: security-advisories@github.com
  - url: >-
      https://github.com/payloadcms/payload/security/advisories/GHSA-p96c-xwx8-3cqj
    label: security-advisories@github.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-10-06T17:14:06.093190Z'
cvssSource: cna
ingestedAt: '2026-10-06T17:09:22.195Z'
---

## Overview

Payload is a free and open source headless content management system. In @payloadcms/plugin-multi-tenant versions before 3.90.0 and canary versions before 4.0.0-canary.34, the default tenant array field access allows an authenticated user to assign the user's own account to other tenants. Deployments that replace the default behavior with secured tenants arrayFieldAccess.create and tenants arrayFieldAccess.update functions are not affected by this behavior. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
