logo

Database

Improper authorization control for web services In @payloadcms/plugin-multi-tenant

Description

Payload has a tenant authorization bypass in Multi-Tenant Plugin

Impact

When using the default tenant array field access, an authenticated user could assign themselves to other tenants.

You are affected if:

    You are using @payloadcms/plugin-multi-tenant

If you configure the tenants arrayFieldAccess.create/update functions, a secured replacement membership field, you are not affected by this specific default behavior.

Patches

Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.

Workarounds

Configure tenants arrayFieldAccess.create and tenants arrayFieldAccess.update so only trusted users authorized for all tenants can modify memberships.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions