CVE-2026-105860 | payloadcms payload up to 3.89.x/4.0.0-canary.33 plugin-multi-tenant arrayFieldAccess.create/arrayFieldAccess.update privileges management

SecurityVulns

A vulnerability labeled as critical has been found in payloadcms payload up to 3.89.x/4.0.0-canary.33. The affected element is the function arrayFieldAccess.create/arrayFieldAccess.update of the component plugin-multi-tenant. The manipulation results in improper privilege management.

This vulnerability is cataloged as CVE-2026-105860. The attack may be launched remotely. There is no exploit available.

The affected component should be upgraded.VulDB Recent EntriesRead More