Description
Payload is a free and open source headless content management system. In @payloadcms/plugin-stripe versions before 3.90.0 and canary versions before 4.0.0-canary.34, an authenticated user who can reach the enabled optional Stripe REST proxy can perform unintended Stripe operations. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
Published: 2026-10-06
Score: 6.4 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized Stripe Operations
Action: Update
AI Analysis

Impact

The vulnerability resides in the Stripe REST proxied endpoint of Payload CMS. An authenticated user who can reach the optional Stripe REST proxy can execute unintended Stripe operations because the proxy fails to enforce proper authorization checks. This type of flaw corresponds to CWE‑749 (Inverted Conditional) and CWE‑862 (Missing Authorization), allowing the attacker to exceed their intended privileges and perform financial or data actions against Stripe accounts.

Affected Systems

Affected systems include Payload CMS and its Stripe plugin. Versions of @payloadcms/plugin‑stripe prior to 3.90.0, as well as the canary channel before 4.0.0‑canary.34, are compromised. The issue also impacts the @payloadcms/payload platform when the Stripe plugin is enabled. Updating to version 3.90.0 or later, or the 4.0.0‑canary.34 release, removes the vulnerability.

Risk and Exploitability

The CVSS score of 6.4 indicates a moderate severity. The EPSS score is not available, so the likelihood of exploitation cannot be quantified from the provided data. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector requires authentication and network reachability to the optional Stripe REST proxy endpoint. Once that condition is met, the attacker can trigger any Stripe operation exposed by the proxy, potentially leading to unauthorized charges, refunds, or data exposure.

Generated by OpenCVE AI on October 6, 2026 at 18:03 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Payload CMS to version 3.90.0 or later
  • Update Payload CMS Stripe plugin to version 3.90.0 or later
  • If the Stripe REST proxy is not required, disable the endpoint or restrict its access to privileged users

Generated by OpenCVE AI on October 6, 2026 at 18:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-r9v2-gg2j-22q5 Payload: Insufficient Access Control in Stripe REST Proxy
History

Tue, 06 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Description Payload is a free and open source headless content management system. In @payloadcms/plugin-stripe versions before 3.90.0 and canary versions before 4.0.0-canary.34, an authenticated user who can reach the enabled optional Stripe REST proxy can perform unintended Stripe operations. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
Title Payload: Insufficient Access Control in Stripe REST Proxy
Weaknesses CWE-749
CWE-862
References
Metrics cvssV4_0

{'score': 6.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-06T16:07:53.896Z

Reserved: 2026-10-05T23:06:29.747Z

Link: CVE-2026-105848

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-06T17:17:20.280

Modified: 2026-10-06T20:03:40.690

Link: CVE-2026-105848

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T18:15:04Z

Weaknesses
  • CWE-749

    Exposed Dangerous Method or Function

  • CWE-862

    Missing Authorization