Security Flaw in Payload CMS's Stripe Plugin Exposes Users to Unintended Operations
CVE-2026-105848

6.4MEDIUM

Key Information:

Vendor

Payloadcms

Vendor
CVE Published:
6 October 2026

What is CVE-2026-105848?

A vulnerability has been identified in the Payload CMS’s Stripe plugin, where an authenticated user with access to the activated optional Stripe REST proxy can perform actions that were unintended and unauthorized. This presents significant security risks, particularly for data integrity and financial transactions. It is crucial for users to update to the fixed versions 3.90.0 or 4.0.0-canary.34 to mitigate potential exploits.

Affected Version(s)

payload < 3.90.0 < 3.90.0

payload >= 4.0.0-canary.0, < 4.0.0-canary.34 < 4.0.0-canary.0, 4.0.0-canary.34

plugin-stripe < 3.90.0 < 3.90.0

References

CVSS V4

Score:
6.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.