CVE-2026-105850
CVE-2026-105850 is a high-severity vulnerability with a CVSS 4.0 base score of 8.8. The underlying weakness is classified as CWE-837.
Key facts
- Severity: High (CVSS 4.0 base score 8.8)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-837
- Published:
- Last modified:
Description
Payload is a free and open source headless content management system. In @payloadcms/plugin-ecommerce versions before 3.90.0 and canary versions before 4.0.0-canary.34, use of the Stripe payment adapter can allow a Stripe order confirmation to be processed more than once under certain conditions. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
Frequently asked questions
- What is CVE-2026-105850?
- Payload is a free and open source headless content management system. In @payloadcms/plugin-ecommerce versions before 3.90.0 and canary versions before 4.0.0-canary.34, use of the Stripe payment adapter can allow a Stripe order confirmation to be processed more than once under certain conditions. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
- How severe is CVE-2026-105850?
- CVE-2026-105850 has a CVSS 4.0 base score of 8.8, rated high severity.
- Is CVE-2026-105850 being actively exploited?
- It is not currently listed in CISA's Known Exploited Vulnerabilities catalog, and no EPSS exploit-prediction score is available yet.
- How do I fix CVE-2026-105850?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2026-105850 published?
- CVE-2026-105850 was published on 2026-10-06.
References
- https://github.com/payloadcms/payload/commit/6c0c4dc9b4ce1ac87b03fbb5dd7356b8559cbc4e
- https://github.com/payloadcms/payload/releases/tag/v3.90.0
- https://github.com/payloadcms/payload/security/advisories/GHSA-8r29-2mp2-pmrw
Other CWE-837 vulnerabilities
- CVE-2025-54315 — High (CVSS 7.1): The Matrix specification before 1.16 (i.e., with a room version before 12) lacks create event uniqueness.
- CVE-2024-11301 — Medium (CVSS 6.5): In lunary-ai/lunary before version 1.6.3, the application allows the creation of evaluators without enforcing a unique…
- CVE-2024-4629 — Medium (CVSS 6.5): A vulnerability was found in Keycloak. This flaw allows attackers to bypass brute force protection by exploiting the…
- CVE-2024-11717 — Medium (CVSS 6.3): Tokens in CTFd used for account activation and password resetting can be used interchangeably for these operations.…
- CVE-2026-45734 — Medium (CVSS 5.3): MyBB is free and open source forum software. Prior to 1.8.40, the built-in CAPTCHA does not consistently enforce…
- CVE-2025-62784 — Medium (CVSS 5.3): InventoryGui is a library for creating chest GUIs for Bukkit/Spigot plugins. Versions before 1.6.5 contain a…