Description
Payload is a free and open source headless content management system. In @payloadcms/plugin-ecommerce versions before 3.90.0 and canary versions before 4.0.0-canary.34, use of the Stripe payment adapter can allow a Stripe order confirmation to be processed more than once under certain conditions. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
Published: 2026-10-06
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: Duplicate order confirmation leading to double charges
Action: Immediate Patch
AI Analysis

Impact

The plugin‑ecommerce service in Payload CMS uses the Stripe payment adapter, and before version 3.90.0 the adapter can process an order confirmation more than once under certain conditions, allowing a duplicate order to be created. This flaw is a constraint violation identified as CWE‑837, resulting in inadvertent double processing of a single payment request. The duplicate processing can cause financial loss, inventory mis‑recording, and customer disputes, compromising the integrity of transaction data.

Affected Systems

The vulnerability affects Payload CMS plugin‑ecommerce and the core Payload CMS product. Versions prior to 3.90.0 of the plugin and prior to 4.0.0‑canary.34 of the core are impacted; these are all releases that have been in use before the patch.

Risk and Exploitability

With a CVSS score of 8.8 the flaw is assessed as high severity. The EPSS score is not available, and the issue is not listed in CISA's KEV catalog, indicating no publicly confirmed exploitation at the time of this analysis. The likely attack vector is a remote attacker sending or replaying a Stripe webhook event that confirms an order; the attacker requires access to the webhook endpoint or a forged Stripe signature, which can be mitigated by validating Stripe signatures and ensuring idempotent order handling.

Generated by OpenCVE AI on October 6, 2026 at 18:01 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Payload CMS plugin‑ecommerce to version 3.90.0 or newer, and upgrade the core Payload CMS to 4.0.0‑canary.34 or newer to apply the vendor‑provided fix.
  • Enable and verify Stripe webhook signatures on your endpoint to ensure that only legitimate Stripe events are processed, preventing forged order confirmations.
  • Configure your back‑end to treat order confirmations as idempotent; record a confirmation flag or check a transaction ID before creating a new order so that duplicate events do not result in new orders.
  • Monitor order logs for repeated confirmation events and investigate any anomalies to detect potential exploitation attempts.

Generated by OpenCVE AI on October 6, 2026 at 18:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-8r29-2mp2-pmrw Payload Ecommerce has an order confirmation validation issue
History

Tue, 06 Oct 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Description Payload is a free and open source headless content management system. In @payloadcms/plugin-ecommerce versions before 3.90.0 and canary versions before 4.0.0-canary.34, use of the Stripe payment adapter can allow a Stripe order confirmation to be processed more than once under certain conditions. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
Title Payload: Order confirmation validation issue in Payload Ecommerce
Weaknesses CWE-837
References
Metrics cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-06T16:28:23.101Z

Reserved: 2026-10-05T23:06:29.748Z

Link: CVE-2026-105850

cve-icon Vulnrichment

Updated: 2026-10-06T16:28:19.406Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-06T17:17:20.693

Modified: 2026-10-06T20:03:40.690

Link: CVE-2026-105850

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T18:15:04Z

Weaknesses
  • CWE-837

    Improper Enforcement of a Single, Unique Action