CVE-2026-105850

CVE-2026-105850 is a high-severity vulnerability with a CVSS 4.0 base score of 8.8. The underlying weakness is classified as CWE-837.

Key facts

Description

Payload is a free and open source headless content management system. In @payloadcms/plugin-ecommerce versions before 3.90.0 and canary versions before 4.0.0-canary.34, use of the Stripe payment adapter can allow a Stripe order confirmation to be processed more than once under certain conditions. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.

Frequently asked questions

What is CVE-2026-105850?
Payload is a free and open source headless content management system. In @payloadcms/plugin-ecommerce versions before 3.90.0 and canary versions before 4.0.0-canary.34, use of the Stripe payment adapter can allow a Stripe order confirmation to be processed more than once under certain conditions. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
How severe is CVE-2026-105850?
CVE-2026-105850 has a CVSS 4.0 base score of 8.8, rated high severity.
Is CVE-2026-105850 being actively exploited?
It is not currently listed in CISA's Known Exploited Vulnerabilities catalog, and no EPSS exploit-prediction score is available yet.
How do I fix CVE-2026-105850?
Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
When was CVE-2026-105850 published?
CVE-2026-105850 was published on 2026-10-06.

References

Other CWE-837 vulnerabilities

Browse all CWE-837 vulnerabilities →