When using the default tenant array field access, an authenticated user could assign themselves to other tenants.
You are affected if:
You are using @payloadcms/plugin-multi-tenant
If you configure the tenants arrayFieldAccess.create/update functions, a secured replacement membership field, you are not affected by this specific default behavior.
// patches
Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.
// workarounds
Configure tenants arrayFieldAccess.create and tenants arrayFieldAccess.update so only trusted users authorized for all tenants can modify memberships.