Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.8
CVE-2026-105850: Payload CMS ecommerce can double‑charge Stripe orders
CVE-2026-105850 · published 3 days ago
Summary
The Payload headless CMS and its ecommerce plugin allow a Stripe order confirmation to be processed more than once in older versions. This could result in customers being charged twice for the same purchase. Upgrade to version 3.90.0 or later (or the 4.0.0‑canary.34 release) to stop the duplicate processing.
What to do
- Update payloadcms plugin-ecommerce to version 3.90.0.
- Update payloadcms plugin-ecommerce to version 4.0.0-canary.34.
- Update payloadcms @payloadcms/plugin-ecommerce to version 3.90.0.
- Update payloadcms @payloadcms/plugin-ecommerce to version 4.0.0-canary.34.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | payloadcms | payload | < 3.90.0 |
| – | @payloadcms | plugin-ecommerce | < 3.90.0 |
| npm | payloadcms | plugin-ecommerce |
< 3.90.0 >= 4.0.0-canary.0, < 4.0.0-canary.34 Fix: upgrade to 3.90.0
|
| npm | payloadcms | @payloadcms/plugin-ecommerce |
< 3.90.0 >= 4.0.0-canary.0, < 4.0.0-canary.34 Fix: upgrade to 3.90.0
|
Original advisory text
Payload Ecommerce has an order confirmation validation issue
Payload is a free and open source headless content management system. In @payloadcms/plugin-ecommerce versions before 3.90.0 and canary versions before 4.0.0-canary.34, use of the Stripe payment adapter can allow a Stripe order confirmation to be processed more than once under certain conditions. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
References
- https://github.com/payloadcms/payload/security/advisories/GHSA-8r29-2mp2-pmrw
- https://github.com/payloadcms/payload/commit/6c0c4dc9b4ce1ac87b03fbb5dd7356b8559...
- https://github.com/payloadcms/payload/releases/tag/v3.90.0
- https://github.com/advisories/GHSA-8r29-2mp2-pmrw
- https://github.com/payloadcms/payload Product
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/105xxx/CVE-2026-1058... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-105850 Vendor Advisory
Internet-facing
14 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker partial control
Severity
8.8
High
Type
CWE-837Improper Enforcement of a Single, Unique Action
Timeline
Published6 Oct 2026
Updated9 Oct 2026
First seen6 Oct 2026
Sources
CVE-2026-105850 · NVD
CVE-2026-105850 · MITRE
GHSA-8r29-2mp2-pmrw · GHSA
GHSA-8r29-2mp2-pmrw · OSV
CVE-2026-105850 · OSV
Track software like this
Free during beta